Impact
When Multi-Attribute Login is enabled in WSO2 products, the login endpoint leaks whether a username exists. For valid accounts the canonical username is returned, while for invalid accounts the original input is echoed. This unintended disclosure allows an attacker to enumerate legitimate user accounts, increasing the effectiveness of brute‑force attempts, phishing campaigns, and social engineering. The vulnerability itself is an information‑disclosure flaw, classified as CWE‑203.
Affected Systems
The flaw affects multiple WSO2 products, including WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, and WSO2 Open Banking IAM. It is triggered when the Multi‑Attribute Login feature is enabled; no specific version details are listed, so the issue may exist across all current releases until addressed in the vendor advisories.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑severity disclosure risk, but based on the description the likely attack vector is remote through the public login interface, making it accessible to anyone who can reach the service. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Nevertheless, the attacker’s ability to enumerate usernames can lower the effort required for subsequent credential‑guessing or social engineering attacks, implying moderate operational risk for organizations that rely on these products.
OpenCVE Enrichment