Where
-Infinity
0
Severity
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques.

Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

First published (updated )
EOL
Feb 28, 2027
Support Ends
Nov 30, 2026

End of life: 2/28/2027, End of support: 11/30/2026, Latest version: 4.12.1

First published (updated )
EOL
Oct 31, 2026
Support Ends
Jul 31, 2026

End of life: 10/31/2026, End of support: 7/31/2026, Latest version: 4.11.6

First published (updated )
EOL
Jun 30, 2026
Support Ends
Mar 31, 2026

End of life: 6/30/2026, End of support: 3/31/2026, Latest version: 4.10.5

First published (updated )
EOL
Feb 28, 2026
Support Ends
Nov 30, 2025

End of life: 2/28/2026, End of support: 11/30/2025, Latest version: 4.9.16

First published (updated )
EOL
Feb 29, 2028
Support Ends
Aug 31, 2027

End of life: 2/29/2028, End of support: 8/31/2027, Latest version: 4.9.16

First published (updated )
EOL
Jun 30, 2025
Support Ends
Mar 31, 2025

End of life: 6/30/2025, End of support: 3/31/2025, Latest version: 4.8.6

First published (updated )
EOL
Feb 28, 2025
Support Ends
Oct 31, 2024

End of life: 2/28/2025, End of support: 10/31/2024, Latest version: 4.7.4

First published (updated )
EOL
Oct 31, 2024
Support Ends
Jun 30, 2024

End of life: 10/31/2024, End of support: 6/30/2024, Latest version: 4.6.22

First published (updated )
EOL
Oct 31, 2024
Support Ends
Jun 30, 2024

End of life: 10/31/2024, End of support: 6/30/2024, Latest version: 4.6.22

First published (updated )
EOL
Feb 28, 2027
Support Ends
Aug 31, 2026

End of life: 2/28/2027, End of support: 8/31/2026, Latest version: 4.6.22

First published (updated )
EOL
Jun 30, 2024
Support Ends
Feb 29, 2024

End of life: 6/30/2024, End of support: 2/29/2024, Latest version: 4.5.3

First published (updated )
EOL
Jun 30, 2024
Support Ends
Feb 29, 2024

End of life: 6/30/2024, End of support: 2/29/2024, Latest version: 4.5.3

First published (updated )
EOL
Oct 8, 2025
Support Ends
Oct 8, 2024

End of life: 10/8/2025, End of support: 10/8/2024, Latest version: 4.4.0-20250919

First published (updated )
EOL
Oct 8, 2025
Support Ends
Oct 8, 2024

End of life: 10/8/2025, End of support: 10/8/2024, Latest version: 4.4.0-20250919

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

First published (updated )
EOL
Mar 7, 2025
Support Ends
Mar 7, 2023

End of life: 3/7/2025, End of support: 3/7/2023, Latest version: 4.3.0-20240424

First published (updated )
EOL
Mar 7, 2025
Support Ends
Mar 7, 2023

End of life: 3/7/2025, End of support: 3/7/2023, Latest version: 4.3.0-20240424

First published (updated )
Severity
9.8
XEE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Withdrawn Advisory This advisory has been withdrawn because it does not affected a package in a supported ecosystem. This link has been maintained to preserve external references.

Original Description

Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

1 / 2
Source: GitHub
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections

1 / 2
First published (updated )
Severity
7.5
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.

1 / 2
First published (updated )
EOL
May 2, 2023
Support Ends
May 2, 2021

End of life: 5/2/2023, End of support: 5/2/2021, Latest version: 4.2.2-20221027

First published (updated )
EOL
May 2, 2023
Support Ends
May 2, 2021

End of life: 5/2/2023, End of support: 5/2/2021, Latest version: 4.2.2-20221027

First published (updated )
EOL
Nov 2, 2022
Support Ends
Nov 2, 2020

End of life: 11/2/2022, End of support: 11/2/2020, Latest version: 4.1.6-20240112

First published (updated )
EOL
Nov 2, 2022
Support Ends
Nov 2, 2020

End of life: 11/2/2022, End of support: 11/2/2020, Latest version: 4.1.6-20240112

First published (updated )
EOL
Mar 20, 2024
Support Ends
Mar 20, 2021

End of life: 3/20/2024, End of support: 3/20/2021, Latest version: 3.9.5-20240122

First published (updated )
EOL
Mar 20, 2024
Support Ends
Mar 20, 2021

End of life: 3/20/2024, End of support: 3/20/2021, Latest version: 3.9.5-20240122

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203