WSO2 Identity Server(IS)等都是美国WSO2公司的产品。WSO2 Identity Server是一款身份认证服务器。WSO2 Identity Server as Key Manager是一个身份服务器。WSO2 Open Banking IAM是一种用于开放银行(Open Banking)领域的身份和访问管理解决方案。 WSO2多款产品存在安全漏洞,该漏洞源于未能验证用户输入,可能导致攻击者推断已注册用户账户的存在,增加暴力攻击和社会工程攻击风险。以下产品受到影响:WSO2 Id
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | Email OTP Authenticator | 1.0.18< 1.0.18.7 |
affected |
1.0.24≤ * |
unaffected | ||
| WSO2 | WSO2 Carbon Authenticator Library For EmailOTP | 4.1.0< 4.1.0.8 |
affected |
4.1.4< 4.1.4.9 |
affected | ||
4.1.22≤ * |
unaffected | ||
3.0.5< 3.0.5.8 |
affected | ||
3.0.24< 3.0.24.6 |
affected | ||
3.0.26< 3.0.26.16 |
affected | ||
| WSO2 | WSO2 Identity Server | < 5.10.0 |
unknown |
5.10.0< 5.10.0.379 |
affected | ||
5.11.0< 5.11.0.426 |
affected | ||
5.11.0< 5.11.0.431 |
affected | ||
6.0.0< 6.0.0.253 |
affected | ||
6.1.0< 6.1.0.254 |
affected | ||
7.0.0< 7.0.0.131 |
affected | ||
| WSO2 | WSO2 Identity Server as Key Manager | < 5.10.0 |
unknown |
5.10.0< 5.10.0.267 |
affected | ||
| WSO2 | WSO2 Open Banking IAM | < 2.0.0 |
unknown |
2.0.0< 2.0.0.318 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 Identity Server | 5.10.0 ~ 5.10.0.379 | - |
|
| WSO2 | WSO2 Open Banking IAM | 2.0.0 ~ 2.0.0.318 | - |
|
| WSO2 | WSO2 Identity Server as Key Manager | 5.10.0 ~ 5.10.0.267 | - |
|
| WSO2 | Email OTP Authenticator | 1.0.18 ~ 1.0.18.7 | - |
|
| WSO2 | WSO2 Carbon Authenticator Library For EmailOTP | 4.1.0 ~ 4.1.0.8 | - |
|
| WSO2 | WSO2 Carbon Authenticator Library For EmailOTP | 3.0.5 ~ 3.0.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-10470 | 8.6 HIGH | Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Una |
| CVE-2025-9973 | 6.4 MEDIUM | Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Orga |
| CVE-2025-8325 | 6.3 MEDIUM | Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Oper |
| CVE-2025-8154 | 5.3 MEDIUM | HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Man |
| CVE-2025-10908 | Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allo |
No comments yet