CVE-2025-14561
9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Summary
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 API Manager | 4.1.0 < 4.1.0.242 | affected |
| WSO2 | WSO2 API Manager | 4.2.0 < 4.2.0.182 | affected |
| WSO2 | WSO2 API Manager | 4.3.0 < 4.3.0.93 | affected |
| WSO2 | WSO2 API Manager | 4.4.0 < 4.4.0.57 | affected |
| WSO2 | WSO2 API Manager | 4.5.0 < 4.5.0.41 | affected |
| WSO2 | WSO2 API Manager | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.42 | affected |
| WSO2 | WSO2 API Control Plane | 4.6.0 < 4.6.0.7 | affected |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.40 | affected |
| WSO2 | WSO2 Traffic Manager | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.40 | affected |
| WSO2 | WSO2 Universal Gateway | 4.6.0 < 4.6.0.6 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.20.74 < 9.20.74.388 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.28.116 < 9.28.116.395 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.29.120 < 9.29.120.213 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.30.67 < 9.30.67.135 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.31.86 < 9.31.86.108 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.32.147 < 9.32.147.5 | affected |
| WSO2 | WSO2 Carbon API Management Implementation | 9.32.160 <= * | unaffected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.20.74 < 9.20.74.388 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.28.116 < 9.28.116.395 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.29.120 < 9.29.120.213 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.30.67 < 9.30.67.135 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.31.86 < 9.31.86.108 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.32.147 < 9.32.147.5 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.32.160 <= * | unaffected |
Weaknesses
- CWE-284: CWE-284: Improper Access Control
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.