Wso2

Identity Server

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 02.06.2025 16:38:33
  • Zuletzt bearbeitet 06.10.2025 13:46:48

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal an...

  • EPSS 8.71%
  • Veröffentlicht 30.05.2025 15:04:09
  • Zuletzt bearbeitet 06.10.2025 13:51:05

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious act...

  • EPSS 0.02%
  • Veröffentlicht 30.05.2025 14:54:32
  • Zuletzt bearbeitet 06.10.2025 13:58:40

A privilege escalation vulnerability exists in multiple [Vendor Name] products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: ...

  • EPSS 0.05%
  • Veröffentlicht 22.05.2025 19:34:05
  • Zuletzt bearbeitet 06.10.2025 13:57:57

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScrip...

  • EPSS 0.09%
  • Veröffentlicht 22.05.2025 19:15:43
  • Zuletzt bearbeitet 06.10.2025 13:57:27

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malici...

  • EPSS 0.05%
  • Veröffentlicht 22.05.2025 18:41:12
  • Zuletzt bearbeitet 06.10.2025 13:57:10

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the lo...

  • EPSS 0.06%
  • Veröffentlicht 22.05.2025 18:26:15
  • Zuletzt bearbeitet 06.10.2025 13:56:53

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, lea...

  • EPSS 0.09%
  • Veröffentlicht 27.02.2025 05:15:13
  • Zuletzt bearbeitet 03.10.2025 16:29:15

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session coo...

  • EPSS 0.35%
  • Veröffentlicht 18.12.2023 09:15:05
  • Zuletzt bearbeitet 21.11.2024 08:44:49

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console....

  • EPSS 0.59%
  • Veröffentlicht 15.12.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:44:39

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.