Improper access control in WSO2 Inc. products - #VU72504
Published: February 22, 2023
Vulnerability identifier: #VU72504
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions when using multiple tenants. A remote user can bypass implemented security restrictions and gain unauthorized access to IDP resources from a different tenant.
Affected software
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
Remediation
Install updates from vendor's website.