3.7

CVE-2025-13736

Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.

The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Manager Version >= 3.1.0 < 3.1.0.351
Wso2Api Manager Version >= 3.2.0 < 3.2.0.455
Wso2Api Manager Version >= 4.0.0 < 4.0.0.375
Wso2Identity Server Version >= 5.10.0 < 5.10.0.380
Wso2Identity Server Version >= 5.11.0 < 5.11.0.427
Wso2Identity Server Version >= 6.0.0 < 6.0.0.254
Wso2Identity Server Version >= 6.1.0 < 6.1.0.255
Wso2Identity Server Version >= 7.0.0 < 7.0.0.132
Wso2Identity Server Version >= 7.1.0 < 7.1.0.40
Wso2Identity Server Version >= 7.2.0 < 7.2.0.2
Wso2Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.371
Wso2Open Banking Am Version >= 2.0.0 < 2.0.0.400
Wso2Open Banking Iam Version >= 2.0.0 < 2.0.0.420
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/
Vendor Advisory