A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/#solution
Workaround
No workaround given by the vendor.
Fri, 17 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 |
Thu, 16 Oct 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations. | |
Title | Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2025-10-17T16:00:41.854Z
Reserved: 2025-08-19T08:48:03.616Z
Link: CVE-2025-9152

Updated: 2025-10-16T12:57:59.271Z

Status : Awaiting Analysis
Published: 2025-10-16T13:15:41.840
Modified: 2025-10-17T16:15:39.550
Link: CVE-2025-9152

No data.

No data.