Security Advisory WSO2-2025-4751/CVE-2025-13647

Published: 2026-05-03

Version: 1.0.0

Severity: Medium

CVSS Score: 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)

CVE IDs: CVE-2025-13647


AFFECTED PRODUCTS

  • WSO2 Identity Server as Key Manager: 5.10.0
  • WSO2 Identity Server: 7.2.0, 7.1.0, 7.0.0, 6.1.0, 6.0.0, 5.11.0, 5.10.0
  • WSO2 Open Banking IAM: 2.0.0

OVERVIEW

Potential information disclosure.

DESCRIPTION

Due to improper validation of the content-type header, an attacker can send a specially crafted request that causes the server to disclose the file path of certificate files, leading to unintended information exposure.

IMPACT

Successful exploitation of this vulnerability could result in the exposure of the file path, potentially facilitating further attacks or compromising the system's confidentiality.

SOLUTION

Community Users (Open Source)

Apply the relevant fixes to your product using the public fix(es) provided below.

If applying the fix or update is not feasible, migrate to the latest unaffected version of the respective WSO2 product(s).

Support Subscription Holders

Update your product to the specified update level, or to a higher update level, to mitigate the identified vulnerability.

Info

WSO2 Support Subscription Holders may use WSO2 Updates in order to apply the fix.

Product Name Product Version Update Level
WSO2 Identity Server 7.2.0 3
WSO2 Identity Server 7.1.0 41
WSO2 Identity Server 7.0.0 133
WSO2 Identity Server 6.1.0 255
WSO2 Identity Server 6.0.0 255
WSO2 Identity Server 5.11.0 428
WSO2 Identity Server 5.10.0 381
WSO2 Identity Server as Key Manager 5.10.0 372
WSO2 Open Banking IAM 2.0.0 421