CVE Database
/

CVE-2025-5605

Back to search

CVE-2025-5605

Published: Oct 24, 2025

Modified: Oct 24, 2025

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.

VendorProductVersions

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.361
affected
5.11.0 - < 5.11.0.414
affected
6.0.0 - < 6.0.0.245
affected
6.1.0 - < 6.1.0.244

+2 more versions

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.6.0
affected
6.6.0 - < 6.6.0.217

WSO2

WSO2 Universal Gateway

affected
4.5.0 - < 4.5.0.10

WSO2

WSO2 Traffic Manager

affected
4.5.0 - < 4.5.0.10

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.334
affected
3.2.0 - < 3.2.0.430
affected
3.2.1 - < 3.2.1.48
affected
4.0.0 - < 4.0.0.346

+5 more versions

WSO2

WSO2 API Control Plane

affected
4.5.0 - < 4.5.0.11

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.354

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.382

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.403

WSO2

org.wso2.carbon:org.wso2.carbon.ui

affected
4.5.3 - < 4.5.3.40
affected
4.6.0 - < 4.6.0.1224
affected
4.6.1 - < 4.6.1.150
affected
4.6.2 - < 4.6.2.664
affected
4.6.3 - < 4.6.3.32

+11 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now