An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.

The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
Advisories

No advisories yet.

Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4115/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4115/#solution


Workaround

No workaround given by the vendor.

History

Fri, 24 Oct 2025 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
Title Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2025-10-24T11:44:58.987Z

Reserved: 2025-06-04T10:51:11.459Z

Link: CVE-2025-5605

cve-icon Vulnrichment

Updated: 2025-10-24T11:44:53.012Z

cve-icon NVD

Status : Received

Published: 2025-10-24T10:15:39.160

Modified: 2025-10-24T12:15:37.950

Link: CVE-2025-5605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.