An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions.

This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.
Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3355/#solution


Workaround

No workaround given by the vendor.

History

Tue, 23 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.
Title Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2025-09-23T10:39:16.195Z

Reserved: 2024-05-07T06:40:12.013Z

Link: CVE-2024-4598

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-23T11:15:39.063

Modified: 2025-09-23T11:15:39.063

Link: CVE-2024-4598

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.