Vulnerability Description
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | >= 4.5.0, < 4.5.0.36 |
| Wso2 | Api Manager | >= 3.1.0, < 3.1.0.349 |
| Wso2 | Identity Server | >= 5.10.0, < 5.10.0.378 |
| Wso2 | Identity Server As Key Manager | >= 5.10.0, < 5.10.0.369 |
| Wso2 | Open Banking Am | >= 2.0.0, < 2.0.0.398 |
| Wso2 | Open Banking Iam | >= 2.0.0, < 2.0.0.418 |
| Wso2 | Traffic Manager | >= 4.5.0, < 4.5.0.34 |
| Wso2 | Universal Gateway | >= 4.5.0, < 4.5.0.34 |
Related Weaknesses (CWE)
References
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisorPatchVendor Advisory
FAQ
What is CVE-2025-12737?
CVE-2025-12737 is a vulnerability with a CVSS score of 8.4 (HIGH). The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and ex...
How severe is CVE-2025-12737?
CVE-2025-12737 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12737?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Identity Server, Wso2 Identity Server As Key Manager, Wso2 Open Banking Am.