8.4

CVE-2025-12737

Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.36
Wso2 ≫ Api Control Plane Version 4.6.0
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.349
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.453
Wso2 ≫ Api Manager Version >= 3.2.1 < 3.2.1.73
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.373
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.236
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.176
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.88
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.52
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.35
Wso2 ≫ Api Manager Version 4.6.0
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.378
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.425
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.252
Wso2 ≫ Identity Server Version >= 6.1.0 < 6.1.0.253
Wso2 ≫ Identity Server Version >= 7.0.0 < 7.0.0.130
Wso2 ≫ Identity Server Version >= 7.1.0 < 7.1.0.38
Wso2 ≫ Identity Server Version 7.2.0
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.369
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.398
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.418
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.34
Wso2 ≫ Traffic Manager Version 4.6.0
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.34
Wso2 ≫ Universal Gateway Version 4.6.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.125
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 8.4 1.7 6
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/
Patch
Vendor Advisory