VulnSea

identity_server_as_key_manager vulnerabilities

CVEs whose affected-version data names the identity_server_as_key_manager package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2025-5802Medium· 5.3
1w ago

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…

SunlitWSO2 · WSO2 API ManagerEPSS 0.25%via NVD
CVE-2025-12737High· 8.4
2w ago

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Succe…

Twilightwso2 · api_control_planeEPSS 0.22%via NVD
CVE-2024-6832Medium· 5.9
1mo ago

The account locking mechanism fails to trigger when secondary user stores are inaccessible

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repe…

Sunlitwso2 · api_control_planeEPSS 0.24%via NVD
CVE-2024-10302Medium· 4.0
1mo ago

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowi…

Sunlitwso2 · api_control_planeEPSS 0.17%via NVD
identity_server_as_key_manager vulnerabilities (CVEs) · VulnSea