CVE 5.7 MEDIUM

Improper Access Control in WSO2 Enterprise Integrator Product via SOAP Admin Services for Logs and User-Store Configuration_CVE-2025-9955

5.7 / 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to be exposed at that privilege level.

While no credentials or sensitive user information are exposed, this vulnerability may allow unauthorized visibility into internal operational details, which could aid in further exploitation or reconnaissance.

Basic Information

ID CVE-2025-9955
Source WSO2
Published Oct 16, 2025 at 12:14
Modified Oct 16, 2025 at 13:29

Affected Product

Vendor WSO2
Product WSO2 Enterprise Integrator
Affected Versions WSO2 WSO2 Enterprise Integrator 6.0.0
WSO2 WSO2 Enterprise Integrator 6.1.0
WSO2 WSO2 Enterprise Integrator 6.1.1
WSO2 WSO2 Enterprise Integrator 6.2.0
WSO2 WSO2 Enterprise Integrator 6.3.0
WSO2 WSO2 Enterprise Integrator 6.4.0
WSO2 WSO2 Enterprise Integrator 6.5.0
WSO2 WSO2 Enterprise Integrator 6.6.0
WSO2 WSO2 Enterprise Service Bus 5.0.0
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.8
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.14
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.16
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.26
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.32
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.36
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.4.40
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.5.3
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.9
WSO2 org.wso2.carbon:org.wso2.carbon.base 4.10
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.8
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.14
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.16
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.26
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.32
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.36
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.4.40
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.5.3
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.9
WSO2 org.wso2.carbon:org.wso2.carbon.server.admin 4.10

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.