{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-03T21:47:29.459","vulnerabilities":[{"cve":{"id":"CVE-2025-9804","sourceIdentifier":"ed10eef1-636d-4fbe-9993-6890dfa878f8","published":"2025-10-16T13:15:42.130","lastModified":"2025-11-21T21:40:09.890","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information.\n\nThis vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected."}],"metrics":{"cvssMetricV31":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*","matchCriteriaId":"DEEA7DB5-BBF7-44A4-9FB6-0D235A44C680"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"C6D7E912-B0C4-4AD2-90CF-6355BA9DEEB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:*","matchCriteriaId":"245D4EB1-F69D-4FAF-94DB-F4B3D3C20539"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"6819491F-C6C3-41C1-B27A-0D0B62224977"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"0D57C8CF-084D-4142-9AF1-7C9F1261A3BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:*","matchCriteriaId":"BC168B6A-B15A-4C3B-A38D-C0B65F24F333"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"8FF14774-8935-4FC9-B5C8-9771B3D6EBFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"1344FB79-0796-445C-A8F3-C03E995925D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"B58251E8-606B-47C8-8E50-9F9FC8C179BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E21D7ABF-C328-425D-B914-618C7628220B"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*","matchCriteriaId":"51465410-6B7C-40FD-A1AB-A14F650A6AC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*","matchCriteriaId":"851470CC-22AB-43E4-9CC6-5E22D49B3572"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*","matchCriteriaId":"9EBAB99E-6F0F-4CE9-A954-E8878826304C"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*","matchCriteriaId":"0B3E6207-B2CF-487C-9CB8-906248B665C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*","matchCriteriaId":"D47B760D-5418-4FB0-88F0-3F78BAFF63E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager_analytics:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"2318B757-4BE3-4A45-9337-12281210964E"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager_analytics:2.1.0:*:*:*:*:*:*:*","matchCriteriaId":"2D5DF76F-1578-4C10-AB38-A01979302B3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"ADEAF56C-4583-40A6-826F-01AC86191AD7"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"04A2A50A-872E-4CC7-BBB7-3E0956176AAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:data_analytics_server:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"941D83A5-1978-49AE-890D-E31980E2D6AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:data_analytics_server:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"5CCDDFAB-C8FC-41C4-9872-667C442F119B"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:enterprise_integrator:6.2.0:*:*:*:*:*:*:*","matchCriteriaId":"66292C25-B0B9-4FCE-9382-57B8F6BB814A"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:enterprise_integrator:6.3.0:*:*:*:*:*:*:*","matchCriteriaId":"709DC7EA-18A6-4B83-84CB-F2499BEB5D2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:enterprise_mobility_manager:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"A9D6FCEF-7685-42DD-B322-AD87B5F37574"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:enterprise_service_bus:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"236C44E3-FAB5-41F2-9884-D17944EBB468"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2689AF3E-01AA-4B79-BA55-6BB3D81E16CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"0375C318-ECD2-4657-A0D7-4A0708266FBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:*","matchCriteriaId":"B9E7D773-A7CE-4AB8-828B-C2E7DC2799AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:*","matchCriteriaId":"CEA63B98-D4B4-4FCD-A869-FE64BC21A1B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"8DA0050E-D5DD-45E5-9F61-DC1BB060EFF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:*","matchCriteriaId":"26542F95-73F3-4906-838E-A66F5DC9DFA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.7.0:*:*:*:*:*:*:*","matchCriteriaId":"60781FE4-38A3-4FEA-9D8B-CADE4B535974"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.8.0:*:*:*:*:*:*:*","matchCriteriaId":"2B169832-A746-49A6-8E92-06624AA9B13A"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.9.0:*:*:*:*:*:*:*","matchCriteriaId":"981D701D-E381-484A-9614-CD0EF0331071"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"F4F126CA-A2F9-44F4-968B-DF71765869E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*","matchCriteriaId":"2153AECE-020A-4C01-B2A6-F9F5D98E7EBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:6.0.0:-:*:*:*:*:*:*","matchCriteriaId":"32CE7893-AD1A-49E5-BD1A-5E9C2DEB8764"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:6.1.0:-:*:*:*:*:*:*","matchCriteriaId":"EA76533A-5BED-4BDC-B348-EB3D3FDFB110"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*","matchCriteriaId":"C1EFBD0F-9664-4EF3-9908-C72B1318F68F"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:7.1.0:-:*:*:*:*:*:*","matchCriteriaId":"A5358E6E-8C01-408D-8692-B1A326DC630F"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_analytics:5.2.0:*:*:*:*:*:*:*","matchCriteriaId":"A1116722-BC4A-4127-9BF5-DB62760BD026"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_analytics:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"D1AB6D32-5BD3-47F0-BDA8-3AEC1C24543F"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_analytics:5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"42BFE7A0-A168-4C1E-8725-41DD500C837E"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_analytics:5.6.0:*:*:*:*:*:*:*","matchCriteriaId":"5508EC5E-BEEA-49A7-BA2E-AEF40ECCB5C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.3.0:*:*:*:*:*:*:*","matchCriteriaId":"104DBA04-538E-4CC5-9B6C-CFEDB40375AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"E4F0F121-700C-4D30-BAFC-960DCC56F08B"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.6.0:*:*:*:*:*:*:*","matchCriteriaId":"2E5761F7-C287-4EC4-A899-C54FB4E80A35"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.7.0:*:*:*:*:*:*:*","matchCriteriaId":"3B184BFC-8E1A-4971-B6D2-C594742AB8CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.9.0:*:*:*:*:*:*:*","matchCriteriaId":"EA51AC1B-0BF6-44F6-B034-CAD4F623DD76"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"6BB34405-A2F1-461A-B51B-E103BB3680A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_am:1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"8CFB56F4-91D1-4FBF-842A-04BB117CAF85"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_am:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"035BF3B3-1AB9-43BC-BB37-68843818EDEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_am:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"94347800-04D2-48C4-ACF0-078A5ACBB063"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"D7C241A3-8EA0-41E4-ABF3-21B9D8E7A5BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_km:1.4.0:*:*:*:*:*:*:*","matchCriteriaId":"E53783F4-60C7-4A92-8951-F8FD51170670"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_km:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"535EFD44-F81C-43B2-B595-81429468637F"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"C7413107-D7B2-49AE-AC46-52E7BFCD6ED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"61636553-C25E-44DF-93D7-EB3E1056D1DC"}]}]}],"references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/","source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","tags":["Vendor Advisory"]}]}}]}