目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-15039— WSO2 Identity Server 处理逻辑错误漏洞

一分钟漏洞结论

影响对象
WSO2 WSO2 Identity Server
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WSO2 Identity Server是美国WSO2公司开源的一款身份认证服务器。 WSO2 Identity Server存在处理逻辑错误漏洞,可能导致攻击者利用漏洞破坏系统的机密性、完整性或可用性。

CVSS 9.4 · Critical EPSS 0.67% · P50

影响版本矩阵 65

厂商产品 版本范围状态
WSO2 WSO2 API Control Plane 4.5.0< 4.5.0.45 affected
4.6.0< 4.6.0.9 affected
WSO2 WSO2 API Manager < 2.6.0 unknown
2.6.0< 2.6.0.150 affected
3.0.0< 3.0.0.180 affected
3.1.0< 3.1.0.356 affected
3.2.0< 3.2.0.460 affected
3.2.1< 3.2.1.79 affected
4.0.0< 4.0.0.381 affected
4.1.0< 4.1.0.244 affected
… +5 条更多
WSO2 WSO2 Carbon Identity Application Authentication Framework 5.12.153< 5.12.153.66 affected
5.12.387< 5.12.387.48 affected
5.14.97< 5.14.97.94 affected
5.17.5< 5.17.5.337 affected
5.17.118< 5.17.118.24 affected
5.18.187< 5.18.187.334 affected
5.18.248< 5.18.248.34 affected
5.23.8< 5.23.8.221 affected
… +11 条更多
WSO2 WSO2 Identity Server < 5.7.0 unknown
5.7.0< 5.7.0.130 affected
5.8.0< 5.8.0.113 affected
5.9.0< 5.9.0.173 affected
5.10.0< 5.10.0.385 affected
5.11.0< 5.11.0.432 affected
6.0.0< 6.0.0.259 affected
6.1.0< 6.1.0.260 affected
… +4 条更多
WSO2 WSO2 Identity Server as Key Manager < 5.7.0 unknown
5.7.0< 5.7.0.129 affected
5.9.0< 5.9.0.179 affected
5.10.0< 5.10.0.376 affected
WSO2 WSO2 Open Banking AM < 1.4.0 unknown
1.4.0< 1.4.0.143 affected
1.5.0< 1.5.0.144 affected
2.0.0< 2.0.0.405 affected
WSO2 WSO2 Open Banking IAM < 2.0.0 unknown
2.0.0< 2.0.0.425 affected
WSO2 WSO2 Open Banking KM < 1.4.0 unknown
1.4.0< 1.4.0.137 affected
1.5.0< 1.5.0.127 affected
WSO2 WSO2 Traffic Manager < 4.5.0 unknown
4.5.0< 4.5.0.43 affected
4.6.0< 4.6.0.8 affected
WSO2 WSO2 Universal Gateway 4.5.0< 4.5.0.43 affected
4.5.0< 4.5.0.44 affected
4.6.0< 4.6.0.8 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-15039 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
来源: CVE Program / CVE List V5
Vulnerability Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
来源: CVE Program / CVE List V5
Vulnerability Title
WSO2 Identity Server 处理逻辑错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
WSO2 Identity Server是美国WSO2公司开源的一款身份认证服务器。 WSO2 Identity Server存在处理逻辑错误漏洞,可能导致攻击者利用漏洞破坏系统的机密性、完整性或可用性。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
WSO2 WSO2 Identity Server 5.7.0 ~ 5.7.0.130 -
WSO2 WSO2 API Manager 2.6.0 ~ 2.6.0.150 -
WSO2 WSO2 Open Banking AM 1.4.0 ~ 1.4.0.143 -
WSO2 WSO2 Open Banking IAM 2.0.0 ~ 2.0.0.425 -
WSO2 WSO2 Traffic Manager 4.5.0 ~ 4.5.0.43 -
WSO2 WSO2 Universal Gateway 4.5.0 ~ 4.5.0.43 -
WSO2 WSO2 API Control Plane 4.5.0 ~ 4.5.0.45 -
WSO2 WSO2 Identity Server as Key Manager 5.7.0 ~ 5.7.0.129 -
WSO2 WSO2 Open Banking KM 1.4.0 ~ 1.4.0.137 -
WSO2 WSO2 Carbon Identity Application Authentication Framework 5.12.153 ~ 5.12.153.66 -

二、漏洞 CVE-2025-15039 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-15039 的情报信息

请登录查看更多情报信息。

CVE-2025-15039 厂商安全公告 (1)

同批安全公告 · WSO2 · 2026-08-06 · 共 19 条

CVE-2026-5430 10.0 CRITICAL WSO2 API Manager 加密问题漏洞
CVE-2026-1728 9.8 CRITICAL WSO2 API Manager 权限许可和访问控制问题漏洞
CVE-2026-3418 9.1 CRITICAL WSO2 API Manager 任意文件上传漏洞
CVE-2025-14561 9.0 CRITICAL WSO2 API Manager 权限许可和访问控制问题漏洞
CVE-2026-3415 8.7 HIGH WSO2 API Manager 资源管理错误漏洞
CVE-2024-6541 6.8 MEDIUM WSO2 Micro Integrator 输入验证错误漏洞
CVE-2024-6832 5.9 MEDIUM WSO2 Identity Server 处理逻辑错误漏洞
CVE-2025-13394 5.4 MEDIUM WSO2 Identity Server 跨站请求伪造漏洞
CVE-2025-12317 5.0 MEDIUM WSO2 Enterprise Integrator 会话机制问题漏洞
CVE-2024-8995 4.9 MEDIUM WSO2 API Manager 会话机制问题漏洞
CVE-2026-0637 4.4 MEDIUM WSO2 API Manager 日志信息泄露漏洞
CVE-2025-13909 4.3 MEDIUM WSO2 Identity Server 输入验证错误漏洞
CVE-2025-11850 4.3 MEDIUM WSO2 Identity Server 安全漏洞
CVE-2025-6508 4.3 MEDIUM WSO2 API Manager 跨站脚本漏洞
CVE-2024-10302 4.0 MEDIUM WSO2 API Manager 输入验证错误漏洞
CVE-2025-14779 3.8 LOW WSO2 Identity Server 权限许可和访问控制问题漏洞
CVE-2025-13736 3.7 LOW WSO2 Identity Server 侧信道信息泄露漏洞
CVE-2025-12627 2.4 LOW WSO2 Identity Server 会话机制问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-15039

暂无评论


发表评论