Wso2
Wso2 Micro Integrator: vulnerabilidades y CVE
Wso2 Micro Integrator tiene 5 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-11093 | Alta (7.2) | 0.44% | — | 5 nov 2025 | An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute… |
| CVE-2024-4598 | Media (6.5) | 0.32% | — | 23 sept 2025 | An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation… |
| CVE-2023-6836 | Alta (7.5) | 0.48% | — | 15 dic 2023 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information. |
| CVE-2022-29548 | Media (6.1) | 41% | — | 21 abr 2022 | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API… |
| CVE-2020-17453 | Media (6.1) | 26% | — | 5 abr 2021 | WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.