Impact
The vulnerability arises when the account locking mechanism fails to trigger if secondary user stores are unavailable, enabling attackers to attempt unlimited authentication attempts against valid accounts in active stores. This flaw is classified as CWE-693, which stems from a failure to maintain consistent system state during lockout processing. The result is that user accounts remain susceptible to brute force attacks, potentially exposing credentials and increasing the risk of compromise.
Affected Systems
Affected products include WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon User Manager Kernel, WSO2 Enterprise Integrator, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. Version information is not specified.
Risk and Exploitability
The CVSS score is 5.9, indicating medium severity, and the EPSS score is not available. It is not listed in CISA's KEV catalog. It is inferred that the exploit requires remote network access to the authentication interfaces and depends on the presence of enabled secondary user stores. Because the lockout counter is never incremented when secondary stores fail, an attacker can repeatedly submit invalid credentials without triggering the lockout, making brute force attacks feasible with sufficient time and bandwidth. While there is no known active exploitation, the conditions for exploitation are straightforward, so the potential risk remains tangible.
OpenCVE Enrichment