← Back to CVE List
Vulnerability Intelligence Report
Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator

CVE-2024-4598

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-1259 ↗CWE-1259 Improper Restriction of Security Token Assignment

Affected Products & Versions

Vendor Product Affected Versions
WSO2 WSO2 API Manager 0 < 3.2.0 (unknown), 3.2.0 < 3.2.0.422 (affected), 3.2.1 < 3.2.1.42 (affected), 4.1.0 < 4.1.0.152 (affected), 4.3.0 < 4.3.0.55 (affected)
WSO2 WSO2 Micro Integrator 0 < 1.2.0 (unknown), 1.2.0 < 1.2.0.157 (affected), 4.1.0 < 4.1.0.95 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.299%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWSO2 LLC · Vendor · USA
Reserved2024-05-07T06:40:12
Published2025-09-23T10:39:16
Last Updated2025-09-23T19:35:33

LINK COPIED TO CLIPBOARD