An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.
A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Oct 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations. | |
Title | Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2025-10-16T12:59:20.054Z
Reserved: 2025-08-19T08:48:03.616Z
Link: CVE-2025-9152

Updated: 2025-10-16T12:57:59.271Z

Status : Awaiting Analysis
Published: 2025-10-16T13:15:41.840
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-9152

No data.

No data.