CVE-2025-9152

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*

History

21 Oct 2025, 18:33

Type Values Removed Values Added
First Time Wso2
Wso2 api Manager
Wso2 api Control Plane
CPE cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/ - Vendor Advisory

17 Oct 2025, 16:15

Type Values Removed Values Added
CWE CWE-306

16 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 13:15

Updated : 2025-10-21 18:33


NVD link : CVE-2025-9152

Mitre link : CVE-2025-9152

CVE.ORG link : CVE-2025-9152


JSON object : View

Products Affected

wso2

  • api_manager
  • api_control_plane
CWE
CWE-306

Missing Authentication for Critical Function