216.73.217.22

CVE-2025-11093

· Published 05/11/2025 19:15 · Modified 04/12/2025 21:09

Labels: CVE-2025-11093 2025-11-05CVE-2025-11093CWE-94ed10eef1-636d-4fbe-9993-6890dfa878f8

Essential information

Published
05/11/2025 19:15
Modified
04/12/2025 21:09
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting engines is limited to administrators in WSO2 Micro Integrator and WSO2 Enterprise Integrator, while in WSO2 API Manager, access extends to both administrators and API creators. This may allow trusted-but-privileged users to perform unauthorized actions or compromise the execution environment.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD
View on NVD

Affected products (CPE)

ProductCPE
wso2 / api control plane cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*
wso2 / enterprise integrator cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*
wso2 / micro integrator cpe:2.3:a:wso2:micro_integrator:4.0.0:*:*:*:*:*:*:*
wso2 / micro integrator cpe:2.3:a:wso2:micro_integrator:4.1.0:*:*:*:*:*:*:*
wso2 / micro integrator cpe:2.3:a:wso2:micro_integrator:4.2.0:*:*:*:*:*:*:*
wso2 / micro integrator cpe:2.3:a:wso2:micro_integrator:4.3.0:*:*:*:*:*:*:*
wso2 / micro integrator cpe:2.3:a:wso2:micro_integrator:4.4.0:*:*:*:*:*:*:*
wso2 / traffic manager cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*
wso2 / universal gateway cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*

References