Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-9955

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/10/2025
Última modificación:
21/10/2025

Descripción

*** Pendiente de traducción *** An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to be exposed at that privilege level.<br /> <br /> While no credentials or sensitive user information are exposed, this vulnerability may allow unauthorized visibility into internal operational details, which could aid in further exploitation or reconnaissance.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:wso2:enterprise_integrator:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_service_bus:5.0.0:*:*:*:*:*:*:*