Wso2

Universal Gateway

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 13.08.2026 13:18:42

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 09.08.2026 14:14:01

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:26
  • Zuletzt bearbeitet 09.08.2026 14:25:39

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...

  • EPSS 0.34%
  • Veröffentlicht 06.07.2026 10:16:56
  • Zuletzt bearbeitet 09.07.2026 13:04:57

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can ...

  • EPSS 0.16%
  • Veröffentlicht 06.07.2026 10:16:53
  • Zuletzt bearbeitet 06.10.2026 22:10:00

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...

  • EPSS 0.17%
  • Veröffentlicht 11.05.2026 10:16:13
  • Zuletzt bearbeitet 27.05.2026 19:41:03

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service A...

  • EPSS 0.19%
  • Veröffentlicht 11.05.2026 10:16:12
  • Zuletzt bearbeitet 27.05.2026 19:42:10

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious ac...

  • EPSS 0.68%
  • Veröffentlicht 19.02.2026 10:05:06
  • Zuletzt bearbeitet 20.02.2026 21:19:23

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malic...

  • EPSS 0.24%
  • Veröffentlicht 18.11.2025 12:05:22
  • Zuletzt bearbeitet 08.12.2025 14:01:26

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain d...

  • EPSS 0.23%
  • Veröffentlicht 18.11.2025 11:28:37
  • Zuletzt bearbeitet 08.12.2025 14:00:21

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the Same...