CVE Database
/

CVE-2025-1862

Back to search

CVE-2025-1862

Published: Sep 26, 2025

Modified: Feb 26, 2026

PUBLISHED

CVSS v3.1

6.7

MEDIUM

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.

VendorProductVersions

WSO2

WSO2 Enterprise Integrator

affected
6.6.0 - < 6.6.0.215

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.347
affected
5.11.0 - < 5.11.0.396
affected
6.0.0 - < 6.0.0.232
affected
6.1.0 - < 6.1.0.224

WSO2

WSO2 Open Banking IAM

affected
2.0.0 - < 2.0.0.391

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.340

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now