8.4
CVE-2025-12737
- EPSS 0.22%
- Veröffentlicht 03.09.2026 13:02:26
- Zuletzt bearbeitet 09.09.2026 20:00:20
- Erkennungen
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.36
Wso2 ≫ Api Control Plane Version 4.6.0
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.349
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.453
Wso2 ≫ Api Manager Version >= 3.2.1 < 3.2.1.73
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.373
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.236
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.176
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.88
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.52
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.35
Wso2 ≫ Api Manager Version 4.6.0
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.378
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.425
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.252
Wso2 ≫ Identity Server Version >= 6.1.0 < 6.1.0.253
Wso2 ≫ Identity Server Version >= 7.0.0 < 7.0.0.130
Wso2 ≫ Identity Server Version >= 7.1.0 < 7.1.0.38
Wso2 ≫ Identity Server Version 7.2.0
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.369
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.398
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.418
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.34
Wso2 ≫ Traffic Manager Version 4.6.0
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.34
Wso2 ≫ Universal Gateway Version 4.6.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.125 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 8.4 | 1.7 | 6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/