CVE-2024-6541
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.
This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-6541",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-6541",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-07T17:45:31.638289Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"affectedData": [
{
"vendor": "WSO2",
"product": "WSO2 Micro Integrator",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "1.2.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.2.0",
"lessThan": "1.2.0.163",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.0.103",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "4.3.0.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Enterprise Integrator",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "6.6.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.6.0",
"lessThan": "6.6.0.205",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 API Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "3.2.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.0.394",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.1",
"lessThan": "3.2.1.21",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.0.311",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.0.167",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.2.0",
"lessThan": "4.2.0.110",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "4.3.0.24",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2-Synapse",
"versions": [
{
"status": "affected",
"version": "2.1.7.wso2v182",
"lessThan": "2.1.7.wso2v182_93",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.1.7.wso2v143",
"lessThan": "2.1.7.wso2v143_119",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.1.7.wso2v183",
"lessThan": "2.1.7.wso2v183_62",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.1.7.wso2v319",
"lessThan": "2.1.7.wso2v319_7",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.1.7.wso2v227",
"lessThan": "2.1.7.wso2v227_88",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.1.7.wso2v271",
"lessThan": "2.1.7.wso2v271_60",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0.wso2v119",
"lessThan": "4.0.0.wso2v119_3",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0.wso2v105",
"lessThan": "4.0.0.wso2v105_3",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0.wso2v20",
"lessThan": "4.0.0.wso2v20_63",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "v4.0.0-wso2v121",
"versionType": "custom",
"lessThanOrEqual": "v4.0.0-wso2v*"
}
],
"packageName": "org.apache.synapse:synapse-core",
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-08-06T22:16:40.557",
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.\n\nThis weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products."
}
],
"lastModified": "2026-08-31T20:14:36.250",
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}