Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
Published Sep 23, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions.
This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.
Affected products
-
Affected
- ≥ 3.2.0, < 3.2.0.422
- ≥ 3.2.1, < 3.2.1.42
- ≥ 4.1.0, < 4.1.0.152
- ≥ 4.3.0, < 4.3.0.55
-
Affected
- ≥ 1.2.0, < 1.2.0.157
- ≥ 4.1.0, < 4.1.0.95
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| WSO2 | WSO2 API Manager | unaffected | Affected
|
| WSO2 | WSO2 Micro Integrator | unaffected | Affected
|
- ≥ 3.2.0 · < 3.2.0.422
- ≥ 3.2.1 · < 3.2.1.42
- ≥ 4.1.0 · < 4.1.0.152
- ≥ 4.3.0 · < 4.3.0.55
- ≥ 1.2.0 · < 1.2.0.157
- ≥ 4.1.0 · < 4.1.0.95
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/#solution
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55022 Advisory
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/ vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55022 | Advisory | |
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/ | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data