CVE-2025-13736
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.
The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-203
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-13736",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-13736",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-06T12:35:31.306851Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"affectedData": [
{
"vendor": "WSO2",
"product": "WSO2 Identity Server as Key Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "5.10.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.10.0",
"lessThan": "5.10.0.371",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Identity Server",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "5.10.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.10.0",
"lessThan": "5.10.0.380",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.11.0",
"lessThan": "5.11.0.427",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.0.0",
"lessThan": "6.0.0.254",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.1.0",
"lessThan": "6.1.0.255",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.0.0",
"lessThan": "7.0.0.132",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.0.40",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.2.0",
"lessThan": "7.2.0.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Open Banking AM",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "2.0.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.0.400",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 API Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "3.1.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.1.0",
"lessThan": "3.1.0.351",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.0.455",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.0.375",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Open Banking IAM",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "2.0.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.0.420",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-06T08:16:28.657",
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/",
"tags": [
"Vendor Advisory"
],
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"description": [
{
"lang": "en",
"value": "CWE-203"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.\n\nThe discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data."
},
{
"lang": "es",
"value": "Cuando el inicio de sesión multiatributo está habilitado, la interfaz de inicio de sesión no logra enmascarar consistentemente la existencia de cuentas de usuario. Para usuarios válidos, el servidor resuelve y muestra su nombre de usuario canónico, mientras que para usuarios inexistentes, se hace eco de la entrada original. Esto ocurre independientemente de la configuración de validate_username.\n\nEl descubrimiento de nombres de usuario válidos puede aumentar el riesgo de ataques de fuerza bruta, ataques de ingeniería social y fuga de información dirigida. Los atacantes pueden aprovechar esta información para elaborar campañas de phishing más efectivas o tácticas de ingeniería social para comprometer cuentas de usuario o extraer datos sensibles."
}
],
"lastModified": "2026-09-29T14:10:00.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D96F9A38-C629-461E-AD8B-0A4EB17C5B31",
"versionEndExcluding": "3.1.0.351",
"versionStartIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A07564C9-76C1-4DE5-80EE-21F3A99C346A",
"versionEndExcluding": "3.2.0.455",
"versionStartIncluding": "3.2.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98444DEE-8EDC-46F3-ACE8-AFEE1CE65157",
"versionEndExcluding": "4.0.0.375",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1384BFE-9B35-4594-9742-FD2D166A5EA5",
"versionEndExcluding": "5.10.0.380",
"versionStartIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E701CF0D-1F05-4F57-806A-E74552365615",
"versionEndExcluding": "5.11.0.427",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5B10494-00DE-4584-9B73-2A67197A41B9",
"versionEndExcluding": "6.0.0.254",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A583BC3-2E0F-4875-A2B1-6831BA427C6A",
"versionEndExcluding": "6.1.0.255",
"versionStartIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D679454-2397-4FBE-A622-32471D759A3D",
"versionEndExcluding": "7.0.0.132",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8214082-4640-45B5-A8B7-8D032EB773A6",
"versionEndExcluding": "7.1.0.40",
"versionStartIncluding": "7.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6ABA50B7-0DEA-4EDB-956A-801505A55AC0",
"versionEndExcluding": "7.2.0.2",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F88006F-22A7-41FF-8DF1-8911FFD21418",
"versionEndExcluding": "5.10.0.371",
"versionStartIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65E8575A-0A7A-4985-946C-85FD67C1DEDC",
"versionEndExcluding": "2.0.0.400",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA459153-BB57-4056-BA82-B22C0853E852",
"versionEndExcluding": "2.0.0.420",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}