cvedb.io
CVE-2025-9955
MEDIUM · CVSS 5.7
EPSS exploitation probability: 0%
Published 2025-10-16T13:15:42.300 · Last modified 2026-06-17T10:10:09.090

Summary

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that are not intended to be exposed at that privilege level. While no credentials or sensitive user information are exposed, this vulnerability may allow unauthorized visibility into internal operational details, which could aid in further exploitation or reconnaissance.

Affected products

wso2 — enterprise_integrator

Does this affect you?

Add your gear to cvedb and we'll alert you only when wso2 ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.