Security features bypass in WSO2 Inc. products - #VU70089
Published: December 9, 2022
Vulnerability identifier: #VU70089
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to introspection of tokens is allowed from any tenant. A remote administrator can access the other tenant resources.
Affected software
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
Remediation
Install updates from vendor's website.
WSO2 Identity Server - update to 6.0