CVE-2025-10907
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code Execution
Record summary
CVE-2025-10907 has a selected CVSS score of 8.4 (high).
Description
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful exploitation may lead to remote code execution (RCE) on the server, depending on how the uploaded file is processed. By default, this vulnerability is only exploitable by users with administrative access to the affected SOAP services.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 5, 2025 · Source: CVE List
Affected products and versions
Showing 12 of 18| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.29 | affected |
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 3.1.0 | unknown |
| 3.1.0 to < 3.1.0.345 | affected | ||
| 3.2.0 to < 3.2.0.448 | affected | ||
| 3.2.1 to < 3.2.1.66 | affected | ||
| 4.0.0 to < 4.0.0.367 | affected | ||
| 4.1.0 to < 4.1.0.230 | affected | ||
| 4.2.0 to < 4.2.0.169 | affected | ||
| 4.3.0 to < 4.3.0.81 | affected | ||
| 4.4.0 to < 4.4.0.45 | affected | ||
| 4.5.0 to < 4.5.0.28 | affected | ||
WSO2 Enterprise IntegratorBrowse WSO2 / WSO2 Enterprise IntegratorDefault status: unaffected | CVE List | Before 6.6.0 | unknown |
| 6.6.0 to < 6.6.0.224 | affected | ||
WSO2 Identity ServerBrowse WSO2 / WSO2 Identity ServerDefault status: unaffected | CVE List | Before 5.10.0 | unknown |
| 5.10.0 to < 5.10.0.375 | affected | ||
| 5.11.0 to < 5.11.0.419 | affected | ||
| 6.0.0 to < 6.0.0.248 | affected | ||
| 6.1.0 to < 6.1.0.248 | affected | ||
| 7.0.0 to < 7.0.0.124 | affected | ||
| 7.1.0 to < 7.1.0.31 | affected | ||
WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 Identity Server as Key ManagerDefault status: unaffected | CVE List | Before 5.10.0 | unknown |
| 5.10.0 to < 5.10.0.365 | affected | ||
WSO2 Micro IntegratorBrowse WSO2 / WSO2 Micro IntegratorDefault status: unaffected | CVE List | Before 4.0.0 | unknown |
| 4.0.0 to < 4.0.0.145 | affected | ||
| 4.1.0 to < 4.1.0.147 | affected | ||
| 4.2.0 to < 4.2.0.141 | affected | ||
WSO2 Open Banking AMBrowse WSO2 / WSO2 Open Banking AMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.394 | affected | ||
WSO2 Open Banking IAMBrowse WSO2 / WSO2 Open Banking IAMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.414 | affected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.27 | affected |
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.27 | affected |
org.apache.ws.commons.axiom.wso2:axiomBrowse WSO2 / org.apache.ws.commons.axiom.wso2:axiomDefault status: unknown | CVE List | 1.2.11 to < 1.2.11.wso2v17_5 | affected |
| 1.2.11-wso2v21 to ≤ * | unaffected | ||
org.jaggeryjs:org.jaggeryjs.jaggery.app.mgtBrowse WSO2 / org.jaggeryjs:org.jaggeryjs.jaggery.app.mgtDefault status: unknown | CVE List | 0.14.13 to < 0.14.13.8 | affected |
| 0.14.16 to < 0.14.16.1 | affected |