Security features bypass in WSO2 Inc. products - #VU70089

 

Security features bypass in WSO2 Inc. products - #VU70089

Published: December 9, 2022


Vulnerability identifier: #VU70089
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to introspection of tokens is allowed from any tenant. A remote administrator can access the other tenant resources.


Affected software

WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager

Remediation

Install updates from vendor's website.

WSO2 Identity Server - update to 6.0

External References

Related Security Bulletins