WSO2 API Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*
- 4.4.0
- 4.3.0
- 4.2.0
- 4.1.0
- 4.0.0
- 3.2.1
- 3.2.0
A content spoofing vulnerability has been identified in multiple WSO2 products, including WSO2 API Manager and WSO2 Identity Server. This vulnerability arises from improper handling of error messages, which are transmitted through URL parameters without adequate validation. As a result, malicious actors can inject arbitrary content into the user interface. Exploiting this vulnerability allows attackers to manipulate error messages displayed in the browser, potentially leading to social engineering attacks by creating deceptive or misleading content.
Exploitation of this vulnerability could enable social engineering attacks by allowing malicious actors to replace genuine error messages with harmful content.
Community users can apply the relevant fixes available on the WSO2 GitHub repository. Support subscription holders should update their product to the specified update level or a higher level to apply the fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.