Vulnerabilities (CVE)

Filtered by vendor Wso2 Subscribe
Filtered by product Enterprise Mobility Manager
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-9804 1 Wso2 15 Api Control Plane, Api Manager, Api Manager Analytics and 12 more 2025-11-21 N/A 9.6 CRITICAL
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
CVE-2017-14651 1 Wso2 17 Api Manager, App Manager, Application Server and 14 more 2025-04-20 3.5 LOW 4.8 MEDIUM
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.