CVE-2024-6541
Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
| CWE | CWE-20 |
| Vendor | wso2 |
| Product | wso2 micro integrator |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for wso2 wso2 micro integrator
Be the first to know when new medium vulnerabilities affecting wso2 wso2 micro integrator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
WSO2 / WSO2 Micro Integrator
1.2.0 < 1.2.0.163 4.1.0 < 4.1.0.103 4.3.0 < 4.3.0.7
WSO2 / WSO2 Enterprise Integrator
6.6.0 < 6.6.0.205
WSO2 / WSO2 API Manager
3.2.0 < 3.2.0.394 3.2.1 < 3.2.1.21 4.0.0 < 4.0.0.311 4.1.0 < 4.1.0.167 4.2.0 < 4.2.0.110 4.3.0 < 4.3.0.24
WSO2 / WSO2-Synapse
2.1.7.wso2v182 < 2.1.7.wso2v182_93 2.1.7.wso2v143 < 2.1.7.wso2v143_119 2.1.7.wso2v183 < 2.1.7.wso2v183_62 2.1.7.wso2v319 < 2.1.7.wso2v319_7 2.1.7.wso2v227 < 2.1.7.wso2v227_88 2.1.7.wso2v271 < 2.1.7.wso2v271_60 4.0.0.wso2v119 < 4.0.0.wso2v119_3 4.0.0.wso2v105 < 4.0.0.wso2v105_3 4.0.0.wso2v20 < 4.0.0.wso2v20_63