Record summary

CVE-2025-10907 has a selected CVSS score of 8.4 (high).

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful exploitation may lead to remote code execution (RCE) on the server, depending on how the uploaded file is processed. By default, this vulnerability is only exploitable by users with administrative access to the affected SOAP services.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 5, 2025 · Source: CVE List

Affected products and versions

Showing 12 of 18
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.5.0 to < 4.5.0.29affected

Default status: unaffected

CVE ListBefore 3.1.0unknown
3.1.0 to < 3.1.0.345affected
3.2.0 to < 3.2.0.448affected
3.2.1 to < 3.2.1.66affected
4.0.0 to < 4.0.0.367affected
4.1.0 to < 4.1.0.230affected
4.2.0 to < 4.2.0.169affected
4.3.0 to < 4.3.0.81affected
4.4.0 to < 4.4.0.45affected
4.5.0 to < 4.5.0.28affected

Default status: unaffected

CVE ListBefore 6.6.0unknown
6.6.0 to < 6.6.0.224affected

Default status: unaffected

CVE ListBefore 5.10.0unknown
5.10.0 to < 5.10.0.375affected
5.11.0 to < 5.11.0.419affected
6.0.0 to < 6.0.0.248affected
6.1.0 to < 6.1.0.248affected
7.0.0 to < 7.0.0.124affected
7.1.0 to < 7.1.0.31affected

WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 Identity Server as Key Manager

Default status: unaffected

CVE ListBefore 5.10.0unknown
5.10.0 to < 5.10.0.365affected

Default status: unaffected

CVE ListBefore 4.0.0unknown
4.0.0 to < 4.0.0.145affected
4.1.0 to < 4.1.0.147affected
4.2.0 to < 4.2.0.141affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.394affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.414affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.27affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.27affected

org.apache.ws.commons.axiom.wso2:axiom

Browse WSO2 / org.apache.ws.commons.axiom.wso2:axiom

Default status: unknown

CVE List1.2.11 to < 1.2.11.wso2v17_5affected
1.2.11-wso2v21 to ≤ *unaffected

org.jaggeryjs:org.jaggeryjs.jaggery.app.mgt

Browse WSO2 / org.jaggeryjs:org.jaggeryjs.jaggery.app.mgt

Default status: unknown

CVE List0.14.13 to < 0.14.13.8affected
0.14.16 to < 0.14.16.1affected

References

2