216.73.217.22

CVE-2024-4598

· Published 23/09/2025 11:15 · Modified 24/09/2025 18:11

Labels: CVE-2024-4598 2025-09-23CVE-2024-4598CWE-1259ed10eef1-636d-4fbe-9993-6890dfa878f8

Essential information

Published
23/09/2025 11:15
Modified
24/09/2025 18:11
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD
View on NVD

Affected products (CPE)

ProductCPE
wso2 / wso2 cpe:2.3:a:wso2:wso2:*:*:*:*:*:*:*:*
wso2 / wso2 enrich mediator cpe:2.3:a:wso2:wso2_enrich_mediator:*:*:*:*:*:*:*:*

References