Impact
The Class Mediator in several WSO2 products fails to properly validate or sanitize messageContext properties when these properties are used to populate dynamic values. This flaw, a CWE‑20 weakness, allows an authenticated user to reference data intended for other system invocations, potentially revealing or altering that data. The primary impact is the disclosure of sensitive information and the unintended modification of system data by users who are already authenticated.
Affected Systems
Affected vendor and product families include WSO2 API Manager, WSO2 Enterprise Integrator, WSO2 Micro Integrator and WSO2‑Synapse. No specific affected versions are listed in the advisory; organizations should check the referenced security announcement for any version ranges or applicable releases.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, and the EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability requires authentication, so the attacker is limited to users who can log in to the system. Nonetheless, because the flaw permits cross‑invocation data leakage or modification, it can lead to significant confidentiality or integrity breaches. The lack of KEV status suggests that no widespread exploitation has been observed, but the potential for misuse remains high for any system that stores sensitive data and relies on messageContext for dynamic behavior.
OpenCVE Enrichment