Security Advisory WSO2-2025-4195

Published: 2026-01-26

Version: 1.0.0

Severity: N/A

CVSS Score: N/A


AFFECTED PRODUCTS

  • WSO2 Integration Control Plane: 1.0.0
  • WSO2 Micro Integrator: 4.3.0, 4.2.0, 4.1.0

OVERVIEW

Essential Security Enhancements.

DESCRIPTION

This update collectively delivers essential enhancements to product security by enforcing the selection of secure algorithms during the negotiation phase of secure communications, rather than allowing the use of less secure alternatives.

IMPACT

The implementation of these security enhancements significantly strengthens the overall protection and integrity of the product, mitigating potential vulnerabilities and ensuring a more robust defense against security threats.

SOLUTION

Community Users (Open Source)

Migrate to the latest unaffected version of the respective WSO2 product(s).

Support Subscription Holders

Update your product to the specified update level, or to a higher update level, to mitigate the identified vulnerability.

Info

WSO2 Support Subscription Holders may use WSO2 Updates in order to apply the fix.

Product Name Product Version Update Level
WSO2 Integration Control Plane 1.0.0 7
WSO2 Micro Integrator 4.3.0 27
WSO2 Micro Integrator 4.2.0 129
WSO2 Micro Integrator 4.1.0 142