CVE Database
/

CVE-2025-10907

Back to search

CVE-2025-10907

Published: Nov 5, 2025

Modified: Nov 5, 2025

PUBLISHED

CVSS v3.1

8.4

HIGH

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful exploitation may lead to remote code execution (RCE) on the server, depending on how the uploaded file is processed. By default, this vulnerability is only exploitable by users with administrative access to the affected SOAP services.

VendorProductVersions

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.345
affected
3.2.0 - < 3.2.0.448
affected
3.2.1 - < 3.2.1.66
affected
4.0.0 - < 4.0.0.367

+5 more versions

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.414

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.394

WSO2

WSO2 API Control Plane

affected
4.5.0 - < 4.5.0.29

WSO2

WSO2 Universal Gateway

affected
4.5.0 - < 4.5.0.27

WSO2

WSO2 Traffic Manager

affected
4.5.0 - < 4.5.0.27

WSO2

WSO2 Micro Integrator

unknown
0 - < 4.0.0
affected
4.0.0 - < 4.0.0.145
affected
4.1.0 - < 4.1.0.147
affected
4.2.0 - < 4.2.0.141

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.375
affected
5.11.0 - < 5.11.0.419
affected
6.0.0 - < 6.0.0.248
affected
6.1.0 - < 6.1.0.248

+2 more versions

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.365

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.6.0
affected
6.6.0 - < 6.6.0.224

WSO2

org.jaggeryjs:org.jaggeryjs.jaggery.app.mgt

affected
0.14.13 - < 0.14.13.8
affected
0.14.16 - < 0.14.16.1

WSO2

org.wso2.carbon.event-processing:org.wso2.carbon.event.simulator.core

affected
2.2.14 - < 2.2.14.7
affected
2.2.17 - < 2.2.17.2
affected
2.3.1 - < 2.3.1.3
unaffected
2.3.19 - <= *

WSO2

org.wso2.carbon.mediation:org.wso2.carbon.mediation.library

affected
4.7.30 - < 4.7.30.47
affected
4.7.61 - < 4.7.61.62
affected
4.7.99 - < 4.7.99.304
affected
4.7.131 - < 4.7.131.22
affected
4.7.175 - < 4.7.175.30

+5 more versions

WSO2

org.wso2.carbon.deployment:org.wso2.carbon.module.mgt

affected
4.9.15 - < 4.9.15.2
affected
4.10.1 - < 4.10.1.1
affected
4.10.9 - < 4.10.9.2
affected
4.11.1 - < 4.11.1.3
affected
4.11.3 - < 4.11.3.3

+5 more versions

WSO2

org.wso2.carbon.deployment:org.wso2.carbon.webapp.mgt

affected
4.10.1 - < 4.10.1.1
affected
4.10.9 - < 4.10.9.2
affected
4.11.1 - < 4.11.1.3
affected
4.11.3 - < 4.11.3.3
affected
4.11.7 - < 4.11.7.5

+4 more versions

WSO2

org.apache.ws.commons.axiom.wso2:axiom

affected
1.2.11 - < 1.2.11.wso2v17_5
unaffected
1.2.11-wso2v21 - <= *

WSO2

org.wso2.carbon:org.wso2.carbon.base

affected
4.5.3 - < 4.5.3.46
affected
4.6.0 - < 4.6.0.2005
affected
4.6.1 - < 4.6.1.153
affected
4.6.2 - < 4.6.2.668
affected
4.6.3 - < 4.6.3.37

+11 more versions

WSO2

org.wso2.carbon:org.wso2.carbon.utils

affected
4.5.3 - < 4.5.3.46
affected
4.6.0 - < 4.6.0.2005
affected
4.6.1 - < 4.6.1.153
affected
4.6.2 - < 4.6.2.668
affected
4.6.3 - < 4.6.3.37

+11 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now