« Volver al listado

CVE-2025-13909

Estado: AnalizadaMedia (4.3)—

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.

Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-13909",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-13909",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-06T12:33:10.840905Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "vendor": "WSO2",
          "product": "WSO2 Identity Server",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.0",
              "lessThan": "7.0.0.134",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.1.0",
              "lessThan": "7.1.0.42",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon Identity Application Authentication Framework",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.78",
              "lessThan": "7.0.78.162",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.8.23",
              "lessThan": "7.8.23.66",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.8.550",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework",
          "defaultStatus": "unknown"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon MagicLink Authenticator Module",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.22",
              "lessThan": "1.1.22.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.1.31",
              "lessThan": "1.1.31.3",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "1.1.45",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.local.auth.magiclink:org.wso2.carbon.identity.application.authenticator.magiclink",
          "defaultStatus": "unknown"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon Abstract OTP Authenticator",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.5",
              "lessThan": "1.0.5.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.0.10",
              "lessThan": "1.0.10.1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "1.0.24",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.auth.otp.commons:org.wso2.carbon.identity.auth.otp.core",
          "defaultStatus": "unknown"
        },
        {
          "vendor": "WSO2",
          "product": "Email OTP Authenticator",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.30",
              "lessThan": "1.0.30.4",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "1.0.51",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.local.auth.emailotp:org.wso2.carbon.identity.local.auth.emailotp",
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-08-06T08:16:28.803",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.\n\nSuccessful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers."
    },
    {
      "lang": "es",
      "value": "El sistema acepta solicitudes de autenticación sin validación suficiente para hacer cumplir el aislamiento de inquilinos al usar OTP por correo electrónico, OTP por SMS o Magic Link como autenticadores de primer factor. Esta falla al separar adecuadamente los datos de usuario entre inquilinos puede llevar a la exposición de información de identificación personal.\n\nLa explotación exitosa permite a un atacante divulgar información de identificación personal de usuarios en diferentes inquilinos, lo que resulta en violaciones de privacidad y posible incumplimiento normativo. Esto puede incluir acceso no autorizado a detalles de usuario como números de móvil."
    }
  ],
  "lastModified": "2026-09-29T14:10:00.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB23A14D-279C-4E26-822D-339A5F9943BC",
              "versionEndExcluding": "7.0.0.134",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "106CFF22-4275-40BD-82FA-56BE38EB1280",
              "versionEndExcluding": "7.1.0.42",
              "versionStartIncluding": "7.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}