WSO2 API Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*
- 4.3.0
- 4.2.0
- 4.1.0
- 4.0.0
- 3.2.1
- 3.2.0
A vulnerability allowing incorrect authorization has been identified in multiple WSO2 products, including WSO2 API Manager, WSO2 Enterprise Integrator, WSO2 Identity Server, and WSO2 Open Banking solutions. This vulnerability allows unauthorized access to versioned files stored in the registry. The issue arises from flawed authorization logic, which a malicious actor with access to the management console can exploit to retrieve versioned files without proper authorization. Successful exploitation could lead to the unauthorized disclosure of configuration or resource files, potentially facilitating further attacks or system reconnaissance.
Exploitation of this vulnerability could result in unauthorized access to versioned files in the registry, allowing for the disclosure of sensitive configuration or resource files that could be used in further attacks or for system reconnaissance.
Users of WSO2 products can apply the relevant fixes available on the WSO2 GitHub repository. Support subscription holders can update their product to the specified update level to apply the fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.