Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-8325

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.9%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2025-8325
  • Wso2 » Api Control Plane » Version: 4.5.0
    cpe:2.3:a:wso2:api_control_plane:4.5.0
  • Wso2 » Api Manager » Version: 3.2.0
    cpe:2.3:a:wso2:api_manager:3.2.0
  • Wso2 » Api Manager » Version: 3.2.0.226
    cpe:2.3:a:wso2:api_manager:3.2.0.226
  • Wso2 » Api Manager » Version: 3.2.0.278
    cpe:2.3:a:wso2:api_manager:3.2.0.278
  • Wso2 » Api Manager » Version: 3.2.0.368
    cpe:2.3:a:wso2:api_manager:3.2.0.368
  • Wso2 » Api Manager » Version: 3.2.0.384
    cpe:2.3:a:wso2:api_manager:3.2.0.384
  • Wso2 » Api Manager » Version: 3.2.0.397
    cpe:2.3:a:wso2:api_manager:3.2.0.397
  • Wso2 » Api Manager » Version: 3.2.0.401
    cpe:2.3:a:wso2:api_manager:3.2.0.401
  • Wso2 » Api Manager » Version: 3.2.0.408
    cpe:2.3:a:wso2:api_manager:3.2.0.408
  • Wso2 » Api Manager » Version: 3.2.0.415
    cpe:2.3:a:wso2:api_manager:3.2.0.415
  • Wso2 » Api Manager » Version: 3.2.0.422
    cpe:2.3:a:wso2:api_manager:3.2.0.422
  • Wso2 » Api Manager » Version: 3.2.0.427
    cpe:2.3:a:wso2:api_manager:3.2.0.427
  • Wso2 » Api Manager » Version: 3.2.0.432
    cpe:2.3:a:wso2:api_manager:3.2.0.432
  • Wso2 » Api Manager » Version: 3.2.0.433
    cpe:2.3:a:wso2:api_manager:3.2.0.433
  • Wso2 » Api Manager » Version: 3.2.0.434
    cpe:2.3:a:wso2:api_manager:3.2.0.434
  • Wso2 » Api Manager » Version: 3.2.1
    cpe:2.3:a:wso2:api_manager:3.2.1
  • Wso2 » Api Manager » Version: 3.2.1.16
    cpe:2.3:a:wso2:api_manager:3.2.1.16
  • Wso2 » Api Manager » Version: 3.2.1.27
    cpe:2.3:a:wso2:api_manager:3.2.1.27
  • Wso2 » Api Manager » Version: 3.2.1.32
    cpe:2.3:a:wso2:api_manager:3.2.1.32
  • Wso2 » Api Manager » Version: 3.2.1.39
    cpe:2.3:a:wso2:api_manager:3.2.1.39
  • Wso2 » Api Manager » Version: 3.2.1.42
    cpe:2.3:a:wso2:api_manager:3.2.1.42
  • Wso2 » Api Manager » Version: 3.2.1.52
    cpe:2.3:a:wso2:api_manager:3.2.1.52
  • Wso2 » Api Manager » Version: 3.2.1.53
    cpe:2.3:a:wso2:api_manager:3.2.1.53
  • Wso2 » Api Manager » Version: 3.2.1.54
    cpe:2.3:a:wso2:api_manager:3.2.1.54
  • Wso2 » Api Manager » Version: 4.0.0
    cpe:2.3:a:wso2:api_manager:4.0.0
  • Wso2 » Api Manager » Version: 4.0.0.168
    cpe:2.3:a:wso2:api_manager:4.0.0.168
  • Wso2 » Api Manager » Version: 4.0.0.217
    cpe:2.3:a:wso2:api_manager:4.0.0.217
  • Wso2 » Api Manager » Version: 4.0.0.280
    cpe:2.3:a:wso2:api_manager:4.0.0.280
  • Wso2 » Api Manager » Version: 4.0.0.293
    cpe:2.3:a:wso2:api_manager:4.0.0.293
  • Wso2 » Api Manager » Version: 4.0.0.305
    cpe:2.3:a:wso2:api_manager:4.0.0.305
  • Wso2 » Api Manager » Version: 4.0.0.310
    cpe:2.3:a:wso2:api_manager:4.0.0.310
  • Wso2 » Api Manager » Version: 4.0.0.318
    cpe:2.3:a:wso2:api_manager:4.0.0.318
  • Wso2 » Api Manager » Version: 4.0.0.319
    cpe:2.3:a:wso2:api_manager:4.0.0.319
  • Wso2 » Api Manager » Version: 4.1.0
    cpe:2.3:a:wso2:api_manager:4.1.0
  • Wso2 » Api Manager » Version: 4.1.0.136
    cpe:2.3:a:wso2:api_manager:4.1.0.136
  • Wso2 » Api Manager » Version: 4.1.0.152
    cpe:2.3:a:wso2:api_manager:4.1.0.152
  • Wso2 » Api Manager » Version: 4.1.0.166
    cpe:2.3:a:wso2:api_manager:4.1.0.166
  • Wso2 » Api Manager » Version: 4.1.0.171
    cpe:2.3:a:wso2:api_manager:4.1.0.171
  • Wso2 » Api Manager » Version: 4.1.0.187
    cpe:2.3:a:wso2:api_manager:4.1.0.187
  • Wso2 » Api Manager » Version: 4.1.0.200
    cpe:2.3:a:wso2:api_manager:4.1.0.200
  • Wso2 » Api Manager » Version: 4.1.0.206
    cpe:2.3:a:wso2:api_manager:4.1.0.206
  • Wso2 » Api Manager » Version: 4.1.0.215
    cpe:2.3:a:wso2:api_manager:4.1.0.215
  • Wso2 » Api Manager » Version: 4.1.0.216
    cpe:2.3:a:wso2:api_manager:4.1.0.216
  • Wso2 » Api Manager » Version: 4.1.0.218
    cpe:2.3:a:wso2:api_manager:4.1.0.218
  • Wso2 » Api Manager » Version: 4.2.0
    cpe:2.3:a:wso2:api_manager:4.2.0
  • Wso2 » Api Manager » Version: 4.2.0.100
    cpe:2.3:a:wso2:api_manager:4.2.0.100
  • Wso2 » Api Manager » Version: 4.2.0.108
    cpe:2.3:a:wso2:api_manager:4.2.0.108
  • Wso2 » Api Manager » Version: 4.2.0.127
    cpe:2.3:a:wso2:api_manager:4.2.0.127
  • Wso2 » Api Manager » Version: 4.2.0.138
    cpe:2.3:a:wso2:api_manager:4.2.0.138
  • Wso2 » Api Manager » Version: 4.2.0.144
    cpe:2.3:a:wso2:api_manager:4.2.0.144
  • Wso2 » Api Manager » Version: 4.2.0.150
    cpe:2.3:a:wso2:api_manager:4.2.0.150
  • Wso2 » Api Manager » Version: 4.2.0.153
    cpe:2.3:a:wso2:api_manager:4.2.0.153
  • Wso2 » Api Manager » Version: 4.2.0.156
    cpe:2.3:a:wso2:api_manager:4.2.0.156
  • Wso2 » Api Manager » Version: 4.2.0.80
    cpe:2.3:a:wso2:api_manager:4.2.0.80
  • Wso2 » Api Manager » Version: 4.3.0
    cpe:2.3:a:wso2:api_manager:4.3.0
  • Wso2 » Api Manager » Version: 4.3.0.16
    cpe:2.3:a:wso2:api_manager:4.3.0.16
  • Wso2 » Api Manager » Version: 4.3.0.39
    cpe:2.3:a:wso2:api_manager:4.3.0.39
  • Wso2 » Api Manager » Version: 4.3.0.51
    cpe:2.3:a:wso2:api_manager:4.3.0.51
  • Wso2 » Api Manager » Version: 4.3.0.55
    cpe:2.3:a:wso2:api_manager:4.3.0.55
  • Wso2 » Api Manager » Version: 4.3.0.57
    cpe:2.3:a:wso2:api_manager:4.3.0.57
  • Wso2 » Api Manager » Version: 4.3.0.65
    cpe:2.3:a:wso2:api_manager:4.3.0.65
  • Wso2 » Api Manager » Version: 4.3.0.66
    cpe:2.3:a:wso2:api_manager:4.3.0.66
  • Wso2 » Api Manager » Version: 4.3.0.67
    cpe:2.3:a:wso2:api_manager:4.3.0.67
  • Wso2 » Api Manager » Version: 4.4.0
    cpe:2.3:a:wso2:api_manager:4.4.0
  • Wso2 » Api Manager » Version: 4.4.0.28
    cpe:2.3:a:wso2:api_manager:4.4.0.28
  • Wso2 » Api Manager » Version: 4.4.0.29
    cpe:2.3:a:wso2:api_manager:4.4.0.29
  • Wso2 » Api Manager » Version: 4.4.0.30
    cpe:2.3:a:wso2:api_manager:4.4.0.30
  • Wso2 » Api Manager » Version: 4.5.0
    cpe:2.3:a:wso2:api_manager:4.5.0
  • Wso2 » Api Manager » Version: 4.5.0.11
    cpe:2.3:a:wso2:api_manager:4.5.0.11
  • Wso2 » Api Manager » Version: 4.5.0.12
    cpe:2.3:a:wso2:api_manager:4.5.0.12
  • Wso2 » Api Manager » Version: 4.5.0.14
    cpe:2.3:a:wso2:api_manager:4.5.0.14
  • Wso2 » Api Manager » Version: 4.5.0.9
    cpe:2.3:a:wso2:api_manager:4.5.0.9
  • Wso2 » Traffic Manager » Version: 4.5.0
    cpe:2.3:a:wso2:traffic_manager:4.5.0
  • Wso2 » Universal Gateway » Version: 4.5.0
    cpe:2.3:a:wso2:universal_gateway:4.5.0


Contact Us

Shodan ® - All rights reserved