Wso2

Identity Server

87 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 08.10.2026 00:09:52
  • Zuletzt bearbeitet 08.10.2026 01:16:32

The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to condu...

  • EPSS 0.22%
  • Veröffentlicht 15.09.2026 09:53:54
  • Zuletzt bearbeitet 18.09.2026 19:13:15

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to d...

  • EPSS 0.25%
  • Veröffentlicht 15.09.2026 09:53:53
  • Zuletzt bearbeitet 18.09.2026 19:13:15

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explic...

  • EPSS 0.22%
  • Veröffentlicht 03.09.2026 13:02:26
  • Zuletzt bearbeitet 09.09.2026 20:00:20

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploit...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 22:16:41
  • Zuletzt bearbeitet 29.09.2026 11:10:00

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privilege...

  • EPSS 0.11%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 12.08.2026 19:29:05

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to t...

  • EPSS 0.37%
  • Veröffentlicht 06.08.2026 08:16:29
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...

  • EPSS 0.1%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie a...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant t...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original inp...