CVE-2025-9152: Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.
A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9152?
CVE-2025-9152 has been classified as a high-severity vulnerability due to its potential to allow unauthorized users to obtain elevated privileges.
How do I fix CVE-2025-9152?
To mitigate CVE-2025-9152, ensure that proper authentication and authorization checks are implemented for the keymanager-operations Dynamic Client Registration (DCR) endpoint.
What software is affected by CVE-2025-9152?
CVE-2025-9152 affects WSO2 API Manager due to insufficient privilege management.
What type of vulnerability is CVE-2025-9152?
CVE-2025-9152 is an improper privilege management vulnerability that allows unauthorized token generation.
Can CVE-2025-9152 be exploited remotely?
Yes, CVE-2025-9152 can potentially be exploited remotely by a malicious actor to gain elevated access.