Home

Description

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.

PUBLISHED Reserved 2025-06-04 | Published 2025-10-24 | Updated 2025-10-24 | Assigner WSO2




MEDIUM: 4.3CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Product status

Default status
unaffected

Any version before 5.10.0
unknown

5.10.0 (custom) before 5.10.0.361
affected

5.11.0 (custom) before 5.11.0.414
affected

6.0.0 (custom) before 6.0.0.245
affected

6.1.0 (custom) before 6.1.0.244
affected

7.0.0 (custom) before 7.0.0.119
affected

7.1.0 (custom) before 7.1.0.25
affected

Default status
unaffected

Any version before 6.6.0
unknown

6.6.0 (custom) before 6.6.0.217
affected

Default status
unaffected

4.5.0 (custom) before 4.5.0.10
affected

Default status
unaffected

4.5.0 (custom) before 4.5.0.10
affected

Default status
unaffected

Any version before 3.1.0
unknown

3.1.0 (custom) before 3.1.0.334
affected

3.2.0 (custom) before 3.2.0.430
affected

3.2.1 (custom) before 3.2.1.48
affected

4.0.0 (custom) before 4.0.0.346
affected

4.1.0 (custom) before 4.1.0.210
affected

4.2.0 (custom) before 4.2.0.148
affected

4.3.0 (custom) before 4.3.0.61
affected

4.4.0 (custom) before 4.4.0.24
affected

4.5.0 (custom) before 4.5.0.10
affected

Default status
unaffected

4.5.0 (custom) before 4.5.0.11
affected

Default status
unaffected

Any version before 5.10.0
unknown

5.10.0 (custom) before 5.10.0.354
affected

Default status
unaffected

Any version before 2.0.0
unknown

2.0.0 (custom) before 2.0.0.382
affected

Default status
unaffected

Any version before 2.0.0
unknown

2.0.0 (custom) before 2.0.0.403
affected

Default status
unknown

4.5.3 (custom) before 4.5.3.40
affected

4.6.0 (custom) before 4.6.0.1224
affected

4.6.1 (custom) before 4.6.1.150
affected

4.6.2 (custom) before 4.6.2.664
affected

4.6.3 (custom) before 4.6.3.32
affected

4.6.4 (custom) before 4.6.4.8
affected

4.7.1 (custom) before 4.7.1.69
affected

4.8.1 (custom) before 4.8.1.33
affected

4.9.0 (custom) before 4.9.0.100
affected

4.9.26 (custom) before 4.9.26.20
affected

4.9.27 (custom) before 4.9.27.4
affected

4.9.28 (custom) before 4.9.28.4
affected

4.10.9 (custom) before 4.10.9.68
affected

4.10.42 (custom) before 4.10.42.10
affected

4.9.29 (custom)
unaffected

4.10.90 (custom)
unaffected

Credits

Noël Maccary reporter

References

security.docs.wso2.com/...ty-advisories/2025/WSO2-2025-4115/ vendor-advisory

cve.org (CVE-2025-5605)

nvd.nist.gov (CVE-2025-5605)

Download JSON