Wso2

Identity Server

87 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 14:10:00

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead t...

  • EPSS 0.19%
  • Veröffentlicht 06.08.2026 08:16:28
  • Zuletzt bearbeitet 29.09.2026 19:10:00

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with tha...

  • EPSS 0.18%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 29.09.2026 14:10:00

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks. This allows a subject to be associated with an u...

  • EPSS 0.12%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 13.08.2026 13:18:42

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization...

  • EPSS 0.24%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 09.08.2026 14:14:01

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:26
  • Zuletzt bearbeitet 09.08.2026 14:25:39

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...

  • EPSS 0.15%
  • Veröffentlicht 20.07.2026 08:06:39
  • Zuletzt bearbeitet 19.08.2026 19:29:34

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacke...

  • EPSS 0.16%
  • Veröffentlicht 06.07.2026 10:16:53
  • Zuletzt bearbeitet 06.10.2026 22:10:00

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...

  • EPSS 0.18%
  • Veröffentlicht 04.07.2026 20:38:49
  • Zuletzt bearbeitet 09.07.2026 18:47:41

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning proc...

  • EPSS 0.16%
  • Veröffentlicht 04.07.2026 12:49:06
  • Zuletzt bearbeitet 06.10.2026 22:10:00

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS appl...