Vulnerability Intelligence Report
Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
CVE-2024-4598
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.
No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1259 ↗CWE-1259 Improper Restriction of Security Token Assignment
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | 0 < 3.2.0 (unknown), 3.2.0 < 3.2.0.422 (affected), 3.2.1 < 3.2.1.42 (affected), 4.1.0 < 4.1.0.152 (affected), 4.3.0 < 4.3.0.55 (affected) |
| WSO2 | WSO2 Micro Integrator | 0 < 1.2.0 (unknown), 1.2.0 < 1.2.0.157 (affected), 4.1.0 < 4.1.0.95 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.299%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WSO2 LLC · Vendor · USA |
| Reserved | 2024-05-07T06:40:12 |
| Published | 2025-09-23T10:39:16 |
| Last Updated | 2025-09-23T19:35:33 |
Community Chatter & Buzz