« Volver al listado

CVE-2025-8325

Estado: AnalizadaAlta (8.8)—

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions.

A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso autenticado (PR:L) a APIs remotas en WSO2 sin privilegios suficientes; escalada de privilegios por bypass RBAC (CWE-281) permitiendo operaciones sensibles no autorizadas en entorno de producción.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-8325",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8325",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-11T12:41:13.926378Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "vendor": "WSO2",
          "product": "WSO2 API Control Plane",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.0.18",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Universal Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.0.17",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Traffic Manager",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.0.17",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 API Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "3.2.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.0",
              "lessThan": "3.2.0.435",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.1",
              "lessThan": "3.2.1.55",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.0.355",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.1.0",
              "lessThan": "4.1.0.219",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.2.0",
              "lessThan": "4.2.0.157",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.3.0",
              "lessThan": "4.3.0.70",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.4.0",
              "lessThan": "4.4.0.33",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.0.17",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon API Management Implementation",
          "versions": [
            {
              "status": "affected",
              "version": "6.7.206",
              "lessThan": "6.7.206.563",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.7.210",
              "lessThan": "6.7.210.55",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.0.174",
              "lessThan": "9.0.174.513",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.20.74",
              "lessThan": "9.20.74.375",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.28.116",
              "lessThan": "9.28.116.352",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.29.120",
              "lessThan": "9.29.120.177",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.30.67",
              "lessThan": "9.30.67.100",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.31.86",
              "lessThan": "9.31.86.58",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "9.32.75",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl",
          "defaultStatus": "unknown"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon API Manager Rest API Utility",
          "versions": [
            {
              "status": "affected",
              "version": "6.7.206",
              "lessThan": "6.7.206.563",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.7.210",
              "lessThan": "6.7.210.55",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.0.174",
              "lessThan": "9.0.174.513",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.20.74",
              "lessThan": "9.20.74.375",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.28.116",
              "lessThan": "9.28.116.352",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.29.120",
              "lessThan": "9.29.120.177",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.30.67",
              "lessThan": "9.30.67.100",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.31.86",
              "lessThan": "9.31.86.58",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "9.32.75",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util",
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-05-11T10:16:13.037",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4401/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-281"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions.\n\nA malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments."
    }
  ],
  "lastModified": "2026-06-17T10:06:45.017",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14673F3A-694F-43A7-A908-89AB43FE5D40",
              "versionEndExcluding": "4.5.0.18",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB859A03-5918-441D-9994-D2FCABC6BA33",
              "versionEndExcluding": "3.2.0.435",
              "versionStartIncluding": "3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B96C6F6B-A9E7-4D9C-914F-72E5EECDF4A5",
              "versionEndExcluding": "3.2.1.55",
              "versionStartIncluding": "3.2.1"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC6CF34B-F7F4-4669-B2FC-31A6CAADA3A9",
              "versionEndExcluding": "4.0.0.355",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59D33891-9333-4121-BE6F-23983E6EB544",
              "versionEndExcluding": "4.1.0.219",
              "versionStartIncluding": "4.1.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "676DEFD1-5C07-4602-91CD-188E3E74D270",
              "versionEndExcluding": "4.2.0.157",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FC7B4FE-F1C1-43FC-940E-9C461BDCFD23",
              "versionEndExcluding": "4.3.0.70",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54762DFE-843A-4C4F-9EFB-C9077A867A6F",
              "versionEndExcluding": "4.4.0.33",
              "versionStartIncluding": "4.4.0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC373117-8394-467A-821F-AF51388FCB8B",
              "versionEndExcluding": "4.5.0.17",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2486C66-55BA-4AA1-82B3-7B5AD5C33C83",
              "versionEndExcluding": "4.5.0.17",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78E12620-9EB3-4512-8688-314A337E9B62",
              "versionEndExcluding": "4.5.0.17",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}