CVE-2025-5605: Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure

Published Oct 24, 2025
·
Updated

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.

The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.

Affected Software

23 affected components
WSO2 Management Console
WSO2 API Control Plane=4.5.0
WSO2 API Manager=3.1.0
WSO2 API Manager=3.2.0
WSO2 API Manager=3.2.1
WSO2 API Manager=4.0.0
WSO2 API Manager=4.1.0
WSO2 API Manager=4.2.0
WSO2 API Manager=4.3.0
WSO2 API Manager=4.4.0
WSO2 API Manager=4.5.0
WSO2 Enterprise Integrator=6.6.0
WSO2 Identity Server=5.10.0
WSO2 Identity Server=5.11.0
WSO2 Identity Server=6.0.0
WSO2 Identity Server=6.1.0
WSO2 Identity Server=7.0.0
WSO2 Identity Server=7.1.0
WSO2 Identity Server as Key Manager=5.10.0
WSO2 Open Banking AM=2.0.0
WSO2 Open Banking Iam=2.0.0
WSO2 Traffic Manager=4.5.0
WSO2 Universal Gateway=4.5.0

Event History

Oct 24, 2025
CVE Published
via MITRE·10:09 AM
Data Sourced
via MITRE·10:09 AM
RemedyDescriptionSeverity
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-5605?

CVE-2025-5605 is considered a critical severity vulnerability due to its potential for unauthorized access and information disclosure.

2

How do I fix CVE-2025-5605?

To fix CVE-2025-5605, update to the latest versions of affected WSO2 products as per the security advisories issued by WSO2.

3

What are the affected products for CVE-2025-5605?

The affected product for CVE-2025-5605 includes the WSO2 Management Console.

4

What impact does CVE-2025-5605 have?

CVE-2025-5605 allows a malicious actor to bypass authentication and potentially access restricted resources, resulting in partial information disclosure.

5

Can CVE-2025-5605 be exploited remotely?

Yes, CVE-2025-5605 can be exploited remotely by an attacker with access to the Management Console.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203