CVE Vulnerabilities

CVE-2025-5605

Authentication Bypass by Spoofing

Published: Oct 24, 2025 | Modified: Nov 21, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.

The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Api_control_plane Wso2 4.5.0 (including) 4.5.0 (including)
Api_manager Wso2 3.1.0 (including) 3.1.0 (including)
Api_manager Wso2 3.2.0 (including) 3.2.0 (including)
Api_manager Wso2 3.2.1 (including) 3.2.1 (including)
Api_manager Wso2 4.0.0 (including) 4.0.0 (including)
Api_manager Wso2 4.1.0 (including) 4.1.0 (including)
Api_manager Wso2 4.2.0 (including) 4.2.0 (including)
Api_manager Wso2 4.3.0 (including) 4.3.0 (including)
Api_manager Wso2 4.4.0 (including) 4.4.0 (including)
Api_manager Wso2 4.5.0 (including) 4.5.0 (including)
Enterprise_integrator Wso2 6.6.0 (including) 6.6.0 (including)
Identity_server Wso2 5.10.0 (including) 5.10.0 (including)
Identity_server Wso2 5.11.0 (including) 5.11.0 (including)
Identity_server Wso2 6.0.0 (including) 6.0.0 (including)
Identity_server Wso2 6.1.0 (including) 6.1.0 (including)
Identity_server Wso2 7.0.0 (including) 7.0.0 (including)
Identity_server Wso2 7.1.0 (including) 7.1.0 (including)
Identity_server_as_key_manager Wso2 5.10.0 (including) 5.10.0 (including)
Open_banking_am Wso2 2.0.0 (including) 2.0.0 (including)
Open_banking_iam Wso2 2.0.0 (including) 2.0.0 (including)
Traffic_manager Wso2 4.5.0 (including) 4.5.0 (including)
Universal_gateway Wso2 4.5.0 (including) 4.5.0 (including)

References