CVE-2025-5717
Last modified
CVE-2025-5717 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | 4.5.0 |
| Wso2 | Api Manager | 3.0.0 |
| Wso2 | Api Manager | 3.1.0 |
| Wso2 | Api Manager | 3.2.0 |
| Wso2 | Api Manager | 3.2.1 |
| Wso2 | Api Manager | 4.0.0 |
| Wso2 | Api Manager | 4.1.0 |
| Wso2 | Api Manager | 4.2.0 |
| Wso2 | Api Manager | 4.3.0 |
| Wso2 | Api Manager | 4.4.0 |
| Wso2 | Api Manager | 4.5.0 |
| Wso2 | Open Banking Am | 2.0.0 |
| Wso2 | Traffic Manager | 4.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5717?
How severe is CVE-2025-5717?
How do I fix CVE-2025-5717?
Are you affected by CVE-2025-5717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
