VendorsWSO2open_banking_iamall versions
Vulnerabilities

WSO2 Open Banking IAM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2025-10611
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Published 2025-10-16 · Analyzed
9.8EPSS 0.008
CVE-2024-6914
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
Published 2025-05-22 · Analyzed
9.8EPSS 0.007
CVE-2025-9312
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
Published 2025-11-18 · Analyzed
9.8EPSS 0.002
CVE-2025-9804
Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
Published 2025-10-16 · Analyzed
9.6EPSS 0.006
CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
9.4EPSS 0.007
CVE-2025-10713
XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
Published 2025-11-05 · Analyzed
9.1EPSS 0.004
CVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
Published 2026-04-16 · Analyzed
9.1EPSS 0.004
CVE-2025-6670
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
Published 2025-11-18 · Analyzed
8.8EPSS 0.002
CVE-2025-10907
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
8.4EPSS 0.006
CVE-2025-12737
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
Published 2026-09-03 · Analyzed
8.4EPSS 0.002
CVE-2024-6832
Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
Published 2026-08-06 · Analyzed
7.5EPSS 0.004
CVE-2025-3125
Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
7.2EPSS 0.008
CVE-2025-1862
Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code Execution
Published 2025-09-26 · Analyzed
7.2EPSS 0.005
CVE-2025-0663
Potential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-Login
Published 2025-09-23 · Analyzed
6.8EPSS 0.002
CVE-2024-7073
Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin Services
Published 2025-06-02 · Analyzed
6.5EPSS 0.002
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2025-10853
Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output Encoding
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-5350
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
Published 2025-10-24 · Analyzed
5.9EPSS 0.006
CVE-2024-10302
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Published 2026-08-06 · Undergoing Analysis
5.8EPSS 0.003
CVE-2024-7096
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
Published 2025-05-30 · Modified
5.4EPSS 0.007
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Published 2025-10-24 · Analyzed
5.3EPSS 0.009
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2025-1396
Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled
Published 2025-09-26 · Analyzed
5.3EPSS 0.003
CVE-2024-0391
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8008
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation
Published 2025-06-02 · Analyzed
5.2EPSS 0.005
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Published 2025-05-30 · Analyzed
4.3EPSS 0.007
CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Published 2025-06-23 · Analyzed
4.3EPSS 0.002
CVE-2025-0672
Authentication Bypass in Multiple WSO2 Products via Stale FIDO Credential Association
Published 2025-09-23 · Analyzed
3.8EPSS 0.002
CVE-2025-13736
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Published 2026-08-06 · Analyzed
3.7EPSS 0.003