Wso2

Api Manager

104 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 06.08.2026 08:16:33
  • Zuletzt bearbeitet 25.09.2026 12:53:05

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthor...

  • EPSS 0.3%
  • Veröffentlicht 06.08.2026 08:16:31
  • Zuletzt bearbeitet 10.08.2026 12:32:08

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products,...

  • EPSS 0.37%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...

  • EPSS 0.11%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 12.08.2026 19:29:05

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to t...

  • EPSS 0.1%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie a...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original inp...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 09.08.2026 14:14:01

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...

  • EPSS 0.12%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 13.08.2026 13:18:42

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:26
  • Zuletzt bearbeitet 09.08.2026 14:25:39

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...

  • EPSS 0.15%
  • Veröffentlicht 20.07.2026 08:06:39
  • Zuletzt bearbeitet 19.08.2026 19:29:34

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacke...