- Description
- In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Analyzed
- Products
- api_manager, identity_server
CVSS 3.1
- Type
- Primary
- Base score
- 7.3
- Impact score
- 5.2
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Severity
- HIGH
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-288
- Hype score
- Not currently trending
CVE-2025-13475 Cross-Tenant Consent Scope Isolation Failure in Multi-Tenanted SaaS Deployments https://t.co/UEee3YBgUD
@VulmonFeeds
13 Jul 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
It is possible to see elevated activities targeting WSO2 Identity Server and API Manager (CVE-2025-13475) https://t.co/vh0PhZ2lDM
@vuldb
7 Jul 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2025-13475 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a… https://t.co/OXU0HXROUO ----- Traducción: CVE-2025-13475 En … https://t.co/utmtNg
@infoflowcloud
4 Jul 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13475 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a… https://t.co/OWhlblVxwp
@CVEnew
4 Jul 2026
649 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EF81870F-4D69-43EC-B261-D1477127E8B3",
"versionEndExcluding": "3.2.0.457",
"versionStartIncluding": "3.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77DFEDF8-3855-4274-9DDF-9BA4C00E047A",
"versionEndExcluding": "3.2.1.76",
"versionStartIncluding": "3.2.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FE7BBD89-3AD6-4DEE-B553-2E7E49536065",
"versionEndExcluding": "5.10.0.382",
"versionStartIncluding": "5.10.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]