CVE-2025-15039
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account.
Leer descripción completaMostrar menos
This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Puntuación base: 9.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access70 %
Vulnerabilidad en API expuesta (WSO2 Identity Server) que bypass autenticación multifactor mediante manipulación del flujo condicional, permitiendo acceso a cuentas de usuario sin completar todos los pasos requeridos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (9)
CWE
- CWE-693
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-15039",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-15039",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-06T12:31:35.881685Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.4,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"affectedData": [
{
"vendor": "WSO2",
"product": "WSO2 Identity Server",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "5.7.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.7.0",
"lessThan": "5.7.0.130",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.8.0",
"lessThan": "5.8.0.113",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.9.0",
"lessThan": "5.9.0.173",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.10.0",
"lessThan": "5.10.0.385",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.11.0",
"lessThan": "5.11.0.432",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.0.0",
"lessThan": "6.0.0.259",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.1.0",
"lessThan": "6.1.0.260",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.0.0",
"lessThan": "7.0.0.138",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.0.45",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.0.49",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.2.0",
"lessThan": "7.2.0.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 API Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "2.6.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.6.0",
"lessThan": "2.6.0.150",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.0.0",
"lessThan": "3.0.0.180",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.1.0",
"lessThan": "3.1.0.356",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.0.460",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.1",
"lessThan": "3.2.1.79",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.0.381",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.0.244",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.2.0",
"lessThan": "4.2.0.184",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "4.3.0.95",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4.0",
"lessThan": "4.4.0.59",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.0.44",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.6.0",
"lessThan": "4.6.0.8",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Open Banking AM",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "1.4.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.4.0",
"lessThan": "1.4.0.143",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.5.0",
"lessThan": "1.5.0.144",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.0.405",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Open Banking IAM",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "2.0.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.0.0.425",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Traffic Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "4.5.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.0.43",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.6.0",
"lessThan": "4.6.0.8",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Universal Gateway",
"versions": [
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.0.43",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.0.44",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.6.0",
"lessThan": "4.6.0.8",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 API Control Plane",
"versions": [
{
"status": "affected",
"version": "4.5.0",
"lessThan": "4.5.0.45",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.6.0",
"lessThan": "4.6.0.9",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Identity Server as Key Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "5.7.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.7.0",
"lessThan": "5.7.0.129",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.9.0",
"lessThan": "5.9.0.179",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.10.0",
"lessThan": "5.10.0.376",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Open Banking KM",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "1.4.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.4.0",
"lessThan": "1.4.0.137",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.5.0",
"lessThan": "1.5.0.127",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Carbon Identity Application Authentication Framework",
"versions": [
{
"status": "affected",
"version": "5.12.153",
"lessThan": "5.12.153.66",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.12.387",
"lessThan": "5.12.387.48",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.14.97",
"lessThan": "5.14.97.94",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.17.5",
"lessThan": "5.17.5.337",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.17.118",
"lessThan": "5.17.118.24",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.18.187",
"lessThan": "5.18.187.334",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.18.248",
"lessThan": "5.18.248.34",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.23.8",
"lessThan": "5.23.8.221",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.24.8",
"lessThan": "5.24.8.29",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.25.92",
"lessThan": "5.25.92.177",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.25.705",
"lessThan": "5.25.705.23",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.25.713",
"lessThan": "5.25.713.12",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.25.724",
"lessThan": "5.25.724.8",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.25.736",
"lessThan": "5.25.736.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.0.78",
"lessThan": "7.0.78.171",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.8.23",
"lessThan": "7.8.23.95",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.8.586",
"lessThan": "7.8.586.21",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "5.25.738",
"versionType": "custom",
"lessThanOrEqual": "5.25.*"
},
{
"status": "unaffected",
"version": "7.8.646",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"packageName": "org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework",
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-08-06T08:16:29.147",
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/",
"tags": [
"Vendor Advisory"
],
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"description": [
{
"lang": "en",
"value": "CWE-693"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.\n\nSuccessful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps."
},
{
"lang": "es",
"value": "El script de autenticación condicional (autenticación adaptativa) no aplica correctamente la finalización de todos los pasos de autenticación requeridos cuando se configura un patrón específico de múltiples pasos que involucra ciertos autenticadores. Esto permite a un atacante eludir los desafíos de autenticación intermedios explotando cómo el script maneja las devoluciones de llamada y la reejecución de los pasos de autenticación.\n\nLa explotación exitosa permite a un actor malicioso obtener acceso no autorizado a una cuenta de usuario objetivo. Esta vulnerabilidad solo puede ser explotada cuando se cumplen todas las siguientes condiciones: el flujo de inicio de sesión de la aplicación contiene un autenticador secundario específico, el script de autenticación condicional está configurado con devoluciones de llamada de eventos particulares y reejecuta un paso de autenticación, el usuario objetivo tiene uno de los autenticadores afectados registrados, y el atacante completa con éxito cualquier paso de autenticación precedente."
}
],
"lastModified": "2026-09-29T14:10:00.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D995D5A2-BA46-4A37-A426-24FEBD31B347",
"versionEndExcluding": "4.5.0.45",
"versionStartIncluding": "4.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D67BE9A3-5C76-4852-8675-FFF32AD070AE",
"versionEndExcluding": "4.6.0.9",
"versionStartIncluding": "4.6.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A7BB442-F48D-4641-8B8C-62920136962A",
"versionEndExcluding": "2.6.0.150",
"versionStartIncluding": "2.6.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CC1A63A-04CC-4B33-B7D0-98F7A468ED20",
"versionEndExcluding": "3.0.0.180",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "779C4DD3-F4C1-4CAE-B7EE-F03A3131D594",
"versionEndExcluding": "3.1.0.356",
"versionStartIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CED55268-DFD9-4A80-8D1A-094122AFC508",
"versionEndExcluding": "3.2.0.460",
"versionStartIncluding": "3.2.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F899F861-8F56-4167-8C77-5918A742C559",
"versionEndExcluding": "3.2.1.79",
"versionStartIncluding": "3.2.1"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60C68B5F-2BD0-43A6-861F-577BD80F422F",
"versionEndExcluding": "4.0.0.381",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06344918-D471-4245-B9FB-69825E99ABA0",
"versionEndExcluding": "4.1.0.244",
"versionStartIncluding": "4.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "905BF4EB-F2AD-4C98-B44B-05410C8C2C75",
"versionEndExcluding": "4.2.0.184",
"versionStartIncluding": "4.2.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29179766-A9E7-4CFF-AF55-5300988D9483",
"versionEndExcluding": "4.3.0.95",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04B57CE9-F224-416E-BB87-242AAA5AEE8B",
"versionEndExcluding": "4.4.0.59",
"versionStartIncluding": "4.4.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E407764-1241-4A14-9EC7-2ABC224EF841",
"versionEndExcluding": "4.5.0.44",
"versionStartIncluding": "4.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7E010B0-0929-40B7-8FC9-8E5B093AF2C7",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5349A5C8-EA3F-4F3F-9A29-DC05D9B8BC00",
"versionEndExcluding": "5.7.0.130",
"versionStartIncluding": "5.7.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "885643C6-A2D5-413C-93F2-13D5CED1FBB1",
"versionEndExcluding": "5.8.0.133",
"versionStartIncluding": "5.8.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4904520D-3B34-458A-B992-DB3F05C4BDA6",
"versionEndExcluding": "5.9.0.173",
"versionStartIncluding": "5.9.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A789202-ADAA-4459-BBB4-0DF61B57E6A9",
"versionEndExcluding": "5.10.0.385",
"versionStartIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90B95E76-04B4-4625-B16B-3FD28632F9CC",
"versionEndExcluding": "5.11.0.432",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAFCB3EB-6778-4B30-B289-F78327917AA5",
"versionEndExcluding": "6.0.0.259",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACF5039C-DDBF-4026-9B9F-3EBDBEF5747E",
"versionEndExcluding": "6.1.0.260",
"versionStartIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB4EADE0-4780-463B-A2DF-D7BD23605D75",
"versionEndExcluding": "7.0.0.138",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92A043AF-9648-471E-8B6C-B28D67FACE92",
"versionEndExcluding": "7.1.0.49",
"versionStartIncluding": "7.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74774992-4FB3-482A-9F6C-DCED20B19B15",
"versionEndExcluding": "7.2.0.7",
"versionStartIncluding": "7.2.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "898D7438-A637-4E37-96F2-7F72342391EC",
"versionEndExcluding": "5.7.0.129",
"versionStartIncluding": "5.7.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE258A94-F8AC-43A9-A94D-1E397DA46417",
"versionEndExcluding": "5.9.0.179",
"versionStartIncluding": "5.9.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF4C333C-084D-4F4A-A0DC-5F5E8BE6E530",
"versionEndExcluding": "5.10.0.376",
"versionStartIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E66821E-A871-461A-83F8-00B8C496846F",
"versionEndExcluding": "1.4.0.143",
"versionStartIncluding": "1.4.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B96B4DC1-A506-42B8-994C-B47EC30732A6",
"versionEndExcluding": "1.5.0.144",
"versionStartIncluding": "1.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0982A3BB-F361-4F00-BAB0-FCB30F7503C3",
"versionEndExcluding": "2.0.0.405",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "613006EB-89F7-4D12-8C42-BA917BB32CE8",
"versionEndExcluding": "2.0.0.425",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92B97896-B673-4240-85B3-0607E3EDF4C5",
"versionEndExcluding": "1.4.0.137",
"versionStartIncluding": "1.4.0"
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F242F2C4-8284-454D-8E46-96501EEB6A9A",
"versionEndExcluding": "1.5.0.127",
"versionStartIncluding": "1.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF30B18A-4390-44B7-ADB7-A5C51D49E0A5",
"versionEndExcluding": "4.5.0.43",
"versionStartIncluding": "4.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "241CBE20-9DC0-4286-8F19-9472C700023F",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0"
},
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C322AC69-86CB-4345-8493-84CA9754FADD",
"versionEndExcluding": "4.5.0.44",
"versionStartIncluding": "4.5.0"
},
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8268BF1-DC35-49E8-823F-0C4CCC351EA6",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}