Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-8154

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2025-8154
  • Wso2 » Api Control Plane » Version: 4.5.0
    cpe:2.3:a:wso2:api_control_plane:4.5.0
  • Wso2 » Api Manager » Version: 4.1.0
    cpe:2.3:a:wso2:api_manager:4.1.0
  • Wso2 » Api Manager » Version: 4.1.0.136
    cpe:2.3:a:wso2:api_manager:4.1.0.136
  • Wso2 » Api Manager » Version: 4.1.0.152
    cpe:2.3:a:wso2:api_manager:4.1.0.152
  • Wso2 » Api Manager » Version: 4.1.0.166
    cpe:2.3:a:wso2:api_manager:4.1.0.166
  • Wso2 » Api Manager » Version: 4.1.0.171
    cpe:2.3:a:wso2:api_manager:4.1.0.171
  • Wso2 » Api Manager » Version: 4.1.0.187
    cpe:2.3:a:wso2:api_manager:4.1.0.187
  • Wso2 » Api Manager » Version: 4.1.0.200
    cpe:2.3:a:wso2:api_manager:4.1.0.200
  • Wso2 » Api Manager » Version: 4.1.0.206
    cpe:2.3:a:wso2:api_manager:4.1.0.206
  • Wso2 » Api Manager » Version: 4.1.0.215
    cpe:2.3:a:wso2:api_manager:4.1.0.215
  • Wso2 » Api Manager » Version: 4.1.0.216
    cpe:2.3:a:wso2:api_manager:4.1.0.216
  • Wso2 » Api Manager » Version: 4.2.0
    cpe:2.3:a:wso2:api_manager:4.2.0
  • Wso2 » Api Manager » Version: 4.2.0.100
    cpe:2.3:a:wso2:api_manager:4.2.0.100
  • Wso2 » Api Manager » Version: 4.2.0.108
    cpe:2.3:a:wso2:api_manager:4.2.0.108
  • Wso2 » Api Manager » Version: 4.2.0.127
    cpe:2.3:a:wso2:api_manager:4.2.0.127
  • Wso2 » Api Manager » Version: 4.2.0.138
    cpe:2.3:a:wso2:api_manager:4.2.0.138
  • Wso2 » Api Manager » Version: 4.2.0.144
    cpe:2.3:a:wso2:api_manager:4.2.0.144
  • Wso2 » Api Manager » Version: 4.2.0.150
    cpe:2.3:a:wso2:api_manager:4.2.0.150
  • Wso2 » Api Manager » Version: 4.2.0.153
    cpe:2.3:a:wso2:api_manager:4.2.0.153
  • Wso2 » Api Manager » Version: 4.2.0.156
    cpe:2.3:a:wso2:api_manager:4.2.0.156
  • Wso2 » Api Manager » Version: 4.2.0.157
    cpe:2.3:a:wso2:api_manager:4.2.0.157
  • Wso2 » Api Manager » Version: 4.2.0.80
    cpe:2.3:a:wso2:api_manager:4.2.0.80
  • Wso2 » Api Manager » Version: 4.3.0
    cpe:2.3:a:wso2:api_manager:4.3.0
  • Wso2 » Api Manager » Version: 4.3.0.16
    cpe:2.3:a:wso2:api_manager:4.3.0.16
  • Wso2 » Api Manager » Version: 4.3.0.39
    cpe:2.3:a:wso2:api_manager:4.3.0.39
  • Wso2 » Api Manager » Version: 4.3.0.51
    cpe:2.3:a:wso2:api_manager:4.3.0.51
  • Wso2 » Api Manager » Version: 4.3.0.55
    cpe:2.3:a:wso2:api_manager:4.3.0.55
  • Wso2 » Api Manager » Version: 4.3.0.57
    cpe:2.3:a:wso2:api_manager:4.3.0.57
  • Wso2 » Api Manager » Version: 4.3.0.65
    cpe:2.3:a:wso2:api_manager:4.3.0.65
  • Wso2 » Api Manager » Version: 4.3.0.66
    cpe:2.3:a:wso2:api_manager:4.3.0.66
  • Wso2 » Api Manager » Version: 4.3.0.67
    cpe:2.3:a:wso2:api_manager:4.3.0.67
  • Wso2 » Api Manager » Version: 4.3.0.70
    cpe:2.3:a:wso2:api_manager:4.3.0.70
  • Wso2 » Api Manager » Version: 4.4.0
    cpe:2.3:a:wso2:api_manager:4.4.0
  • Wso2 » Api Manager » Version: 4.4.0.28
    cpe:2.3:a:wso2:api_manager:4.4.0.28
  • Wso2 » Api Manager » Version: 4.4.0.29
    cpe:2.3:a:wso2:api_manager:4.4.0.29
  • Wso2 » Api Manager » Version: 4.4.0.30
    cpe:2.3:a:wso2:api_manager:4.4.0.30
  • Wso2 » Api Manager » Version: 4.4.0.33
    cpe:2.3:a:wso2:api_manager:4.4.0.33
  • Wso2 » Api Manager » Version: 4.5.0
    cpe:2.3:a:wso2:api_manager:4.5.0
  • Wso2 » Api Manager » Version: 4.5.0.11
    cpe:2.3:a:wso2:api_manager:4.5.0.11
  • Wso2 » Api Manager » Version: 4.5.0.12
    cpe:2.3:a:wso2:api_manager:4.5.0.12
  • Wso2 » Api Manager » Version: 4.5.0.14
    cpe:2.3:a:wso2:api_manager:4.5.0.14
  • Wso2 » Api Manager » Version: 4.5.0.17
    cpe:2.3:a:wso2:api_manager:4.5.0.17
  • Wso2 » Api Manager » Version: 4.5.0.9
    cpe:2.3:a:wso2:api_manager:4.5.0.9
  • Wso2 » Traffic Manager » Version: 4.5.0
    cpe:2.3:a:wso2:traffic_manager:4.5.0
  • Wso2 » Universal Gateway » Version: 4.5.0
    cpe:2.3:a:wso2:universal_gateway:4.5.0


Contact Us

Shodan ® - All rights reserved