Security Advisory WSO2-2022-2281

Published: 2026-01-26

Version: 1.0.0

Severity: Medium

CVSS Score: 6.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)


AFFECTED PRODUCTS

  • WSO2 API Manager: 4.2.0, 4.1.0, 4.0.0, 3.2.0, 3.1.0
  • WSO2 Identity Server as Key Manager: 5.10.0
  • WSO2 Identity Server: 6.0.0, 5.11.0, 5.10.0
  • WSO2 Open Banking AM: 2.0.0
  • WSO2 Open Banking IAM: 2.0.0

OVERVIEW

Unauthorized access to service provider via the deactivated tenant.

DESCRIPTION

Due to the improper tenant status validation, users in the deactivated tenant can continually access the service provider when it is configured to use Client Credential grant type or an External Federated Identity Provider even though the tenant status is deactivated.

IMPACT

By leveraging this vulnerability a malicious actor could get unauthorized access for the data and services which are no longer available for users in the deactivated tenant. However the vulnerable behavior only exists when the service provider is configured to access using Client Credential Grant Type or External Federated Identity Provider.

SOLUTION

Community Users (Open Source)

Migrate to the latest unaffected version of the respective WSO2 product(s).

Support Subscription Holders

Update your product to the specified update level, or to a higher update level, to mitigate the identified vulnerability.

Info

WSO2 Support Subscription Holders may use WSO2 Updates in order to apply the fix.

Product Name Product Version Update Level
WSO2 API Manager 4.2.0 150
WSO2 API Manager 4.1.0 216
WSO2 API Manager 4.0.0 168
WSO2 API Manager 3.2.0 226
WSO2 API Manager 3.1.0 181
WSO2 Identity Server 6.0.0 231
WSO2 Identity Server 5.11.0 208
WSO2 Identity Server 5.10.0 194
WSO2 Identity Server as Key Manager 5.10.0 193
WSO2 Open Banking AM 2.0.0 220
WSO2 Open Banking IAM 2.0.0 232