Description
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- WSO2 / WSO2 API Control Plane4.5.0 – 4.5.0.20
- WSO2 / WSO2 API Manager3.2.0 – 3.2.0.437
- WSO2 / WSO2 API Manager3.2.1 – 3.2.1.57
- WSO2 / WSO2 API Manager4.0.0 – 4.0.0.357
- WSO2 / WSO2 API Manager4.1.0 – 4.1.0.221
- WSO2 / WSO2 API Manager0 – 3.2.0
- WSO2 / WSO2 API Manager4.3.0 – 4.3.0.72
- WSO2 / WSO2 API Manager4.4.0 – 4.4.0.35
- WSO2 / WSO2 API Manager4.5.0 – 4.5.0.19
- WSO2 / WSO2 API Manager4.2.0 – 4.2.0.159