- Description
- The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Analyzed
- Products
- api_control_plane, api_manager, traffic_manager, universal_gateway
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-281
- Hype score
- Not currently trending
CVE-2025-8325 The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing i… https://t.co/P4YKfvdUlQ
@CVEnew
11 May 2026
185 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-8325 Insufficient Role-Based Access Control in WSO2 API Manager 3.x Gateway APIs https://t.co/Nt4LeL4VdD
@VulmonFeeds
11 May 2026
175 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"matchCriteriaId": "14673F3A-694F-43A7-A908-89AB43FE5D40",
"versionEndExcluding": "4.5.0.18",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BB859A03-5918-441D-9994-D2FCABC6BA33",
"versionEndExcluding": "3.2.0.435",
"versionStartIncluding": "3.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B96C6F6B-A9E7-4D9C-914F-72E5EECDF4A5",
"versionEndExcluding": "3.2.1.55",
"versionStartIncluding": "3.2.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "AC6CF34B-F7F4-4669-B2FC-31A6CAADA3A9",
"versionEndExcluding": "4.0.0.355",
"versionStartIncluding": "4.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "59D33891-9333-4121-BE6F-23983E6EB544",
"versionEndExcluding": "4.1.0.219",
"versionStartIncluding": "4.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "676DEFD1-5C07-4602-91CD-188E3E74D270",
"versionEndExcluding": "4.2.0.157",
"versionStartIncluding": "4.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3FC7B4FE-F1C1-43FC-940E-9C461BDCFD23",
"versionEndExcluding": "4.3.0.70",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "54762DFE-843A-4C4F-9EFB-C9077A867A6F",
"versionEndExcluding": "4.4.0.33",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "AC373117-8394-467A-821F-AF51388FCB8B",
"versionEndExcluding": "4.5.0.17",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C2486C66-55BA-4AA1-82B3-7B5AD5C33C83",
"versionEndExcluding": "4.5.0.17",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "78E12620-9EB3-4512-8688-314A337E9B62",
"versionEndExcluding": "4.5.0.17",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]