Back to overview

CVE-2025-9152

CRITICAL
9.8
CVSS 3.1
Description
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

Metadata

CVE ID
CVE-2025-9152
State
PUBLISHED
Assigner
WSO2
Reserved
2025-08-19 08:48 UTC
Published
2025-10-16 12:37 UTC
Last updated
2025-10-17 16:00 UTC
Primary CWE
CWE-306
CWE-306 Missing Authentication for Critical Function
Vendor / Product
WSO2 / WSO2 API Manager
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
WSO2 WSO2 API Control Plane 4.5.0 < 4.5.0.20
WSO2 WSO2 API Manager 0 < 3.2.0, 3.2.0 < 3.2.0.437, 3.2.1 < 3.2.1.57, 4.0.0 < 4.0.0.357 …
Weakness (CWE)
CWESourceDescription
CWE-306 adp CWE-306 Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview