CVE-2025-14561
9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Summary
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 API Manager | 4.1.0 < 4.1.0.242 | affected |
| WSO2 | WSO2 API Manager | 4.2.0 < 4.2.0.182 | affected |
| WSO2 | WSO2 API Manager | 4.3.0 < 4.3.0.93 | affected |
| WSO2 | WSO2 API Manager | 4.4.0 < 4.4.0.57 | affected |
| WSO2 | WSO2 API Manager | 4.5.0 < 4.5.0.41 | affected |
| WSO2 | WSO2 API Manager | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.42 | affected |
| WSO2 | WSO2 API Control Plane | 4.6.0 < 4.6.0.7 | affected |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.40 | affected |
| WSO2 | WSO2 Traffic Manager | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.40 | affected |
| WSO2 | WSO2 Universal Gateway | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.20.74 < 9.20.74.388 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.28.116 < 9.28.116.395 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.29.120 < 9.29.120.213 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.30.67 < 9.30.67.135 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.31.86 < 9.31.86.108 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.32.147 < 9.32.147.5 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.32.160 <= * | unaffected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.20.74 < 9.20.74.388 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.28.116 < 9.28.116.395 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.29.120 < 9.29.120.213 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.30.67 < 9.30.67.135 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.31.86 < 9.31.86.108 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.32.147 < 9.32.147.5 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.32.160 <= * | unaffected |
Weaknesses
- CWE-284: CWE-284: Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.