CVE-2025-5605: Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.
The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5605?
CVE-2025-5605 is considered a critical severity vulnerability due to its potential for unauthorized access and information disclosure.
How do I fix CVE-2025-5605?
To fix CVE-2025-5605, update to the latest versions of affected WSO2 products as per the security advisories issued by WSO2.
What are the affected products for CVE-2025-5605?
The affected product for CVE-2025-5605 includes the WSO2 Management Console.
What impact does CVE-2025-5605 have?
CVE-2025-5605 allows a malicious actor to bypass authentication and potentially access restricted resources, resulting in partial information disclosure.
Can CVE-2025-5605 be exploited remotely?
Yes, CVE-2025-5605 can be exploited remotely by an attacker with access to the Management Console.