CVE-2025-5717
Authenticated Remote Code Execution in Multiple WSO2 Products via Event Processor Admin Service
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server.
Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
WSO2 · Siddhi Extension Evaluate ScriptsWSO2 · WSO2 API Control PlaneWSO2 · WSO2 API ManagerWSO2 · WSO2 Open Banking AMWSO2 · WSO2 Traffic ManagerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →