Wso2

Api Manager

99 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 06.08.2026 22:17:03
  • Zuletzt bearbeitet 07.08.2026 18:17:14

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative ...

  • EPSS 0.34%
  • Veröffentlicht 06.08.2026 22:17:03
  • Zuletzt bearbeitet 07.08.2026 18:17:14

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML conte...

  • EPSS 0.2%
  • Veröffentlicht 06.08.2026 22:16:42
  • Zuletzt bearbeitet 07.08.2026 18:17:06

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors...

  • EPSS 0.39%
  • Veröffentlicht 06.08.2026 22:16:41
  • Zuletzt bearbeitet 07.08.2026 18:17:06

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerabil...

  • EPSS 0.26%
  • Veröffentlicht 06.08.2026 22:16:40
  • Zuletzt bearbeitet 07.08.2026 18:17:05

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should...

  • EPSS 0.22%
  • Veröffentlicht 06.08.2026 08:16:33
  • Zuletzt bearbeitet 10.08.2026 12:35:29

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthor...

  • EPSS 0.3%
  • Veröffentlicht 06.08.2026 08:16:31
  • Zuletzt bearbeitet 10.08.2026 12:32:08

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products,...

  • EPSS 0.11%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 12.08.2026 19:29:05

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to t...

  • EPSS 0.37%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 12.08.2026 19:32:37

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 12.08.2026 19:36:22

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original inp...