Impact
The flaw lies in insufficient validation of user-supplied input during certain administrative operations in the Carbon Console. An administrator who can invoke these actions can inject code that is executed on the host, leading to a full compromise of the affected system. This vulnerability is categorized as CWE‑78 and allows the execution of arbitrary code.
Affected Systems
The vulnerability affects several WSO2 products: WSO2 API Control Plane, WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. An explicit list of affected product versions is not provided in the advisory.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The exploit requires an attacker to have administrative privileges and access to the Carbon Console; it is carried out remotely through the administrative interface. Once leveraged, the attacker can execute arbitrary code on the host system.
OpenCVE Enrichment