3.7
CVE-2025-13736
- EPSS 0.17%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 12.08.2026 19:36:22
- CVE-Watchlists
- Unerledigt
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration. The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.351
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.455
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.375
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.380
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.427
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.254
Wso2 ≫ Identity Server Version >= 6.1.0 < 6.1.0.255
Wso2 ≫ Identity Server Version >= 7.0.0 < 7.0.0.132
Wso2 ≫ Identity Server Version >= 7.1.0 < 7.1.0.40
Wso2 ≫ Identity Server Version >= 7.2.0 < 7.2.0.2
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.371
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.400
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.420
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.067 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/