VYPR
Unrated severityNVD Advisory· Published Oct 16, 2025· Updated Oct 16, 2025

Improper Access Control in WSO2 Enterprise Integrator Product via SOAP Admin Services for Logs and User-Store Configuration

CVE-2025-9955

Description

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to be exposed at that privilege level.

While no credentials or sensitive user information are exposed, this vulnerability may allow unauthorized visibility into internal operational details, which could aid in further exploitation or reconnaissance.

Affected products

4
  • WSO2/org.wso2.carbon:org.wso2.carbon.basev5
    Range: 4.4.8
  • WSO2/org.wso2.carbon:org.wso2.carbon.server.adminv5
    Range: 4.4.8
  • WSO2/WSO2 Enterprise Integratorv5
    Range: 6.0.0
  • WSO2/WSO2 Enterprise Service Busv5
    Range: 5.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.