« Volver al listado

CVE-2024-6541

Estado: AplazadaMedia (6.8)—

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.

This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6541",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6541",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-07T17:45:31.638289Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "vendor": "WSO2",
          "product": "WSO2 Micro Integrator",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "1.2.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.2.0",
              "lessThan": "1.2.0.163",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.1.0",
              "lessThan": "4.1.0.103",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.0",
              "lessThan": "4.3.0.7",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Enterprise Integrator",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "6.6.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.6.0",
              "lessThan": "6.6.0.205",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 API Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "3.2.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.0",
              "lessThan": "3.2.0.394",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.1",
              "lessThan": "3.2.1.21",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.0.311",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.1.0",
              "lessThan": "4.1.0.167",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.2.0",
              "lessThan": "4.2.0.110",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.0",
              "lessThan": "4.3.0.24",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2-Synapse",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.7.wso2v182",
              "lessThan": "2.1.7.wso2v182_93",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.1.7.wso2v143",
              "lessThan": "2.1.7.wso2v143_119",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.1.7.wso2v183",
              "lessThan": "2.1.7.wso2v183_62",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.1.7.wso2v319",
              "lessThan": "2.1.7.wso2v319_7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.1.7.wso2v227",
              "lessThan": "2.1.7.wso2v227_88",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.1.7.wso2v271",
              "lessThan": "2.1.7.wso2v271_60",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0.wso2v119",
              "lessThan": "4.0.0.wso2v119_3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0.wso2v105",
              "lessThan": "4.0.0.wso2v105_3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0.wso2v20",
              "lessThan": "4.0.0.wso2v20_63",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "v4.0.0-wso2v121",
              "versionType": "custom",
              "lessThanOrEqual": "v4.0.0-wso2v*"
            }
          ],
          "packageName": "org.apache.synapse:synapse-core",
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-08-06T22:16:40.557",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.\n\nThis weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products."
    }
  ],
  "lastModified": "2026-08-31T20:14:36.250",
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}