📦 Enterprise Integrator

by Wso2

🔍 What is Enterprise Integrator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-29464

CRITICAL CVSS 9.8 Apr 18, 2022

CVE-2022-29464 is a critical unrestricted file upload vulnerability in multiple WSO2 products that allows attackers to upload malicious files to web-accessible directories via directory traversal. Thi...

CVE-2025-6670

HIGH CVSS 8.8 Nov 18, 2025

This CSRF vulnerability in WSO2 products allows attackers to trick authenticated users into performing unintended administrative actions by clicking malicious links. It affects WSO2 products with expo...

CVE-2025-11093

HIGH CVSS 8.4 Nov 5, 2025

This CVE describes an arbitrary code execution vulnerability in WSO2 integration products where authenticated users with elevated privileges (administrators in WSO2 Micro/Enterprise Integrator, admini...

CVE-2025-10907

HIGH CVSS 8.4 Nov 5, 2025

An arbitrary file upload vulnerability in WSO2 products allows authenticated administrators to upload malicious files to user-controlled locations via SOAP admin services. This can lead to remote code...

CVE-2025-10713

MEDIUM CVSS 6.5 Nov 5, 2025

An XML External Entity (XXE) vulnerability in multiple WSO2 products allows attackers to read sensitive server files or cause denial-of-service. The vulnerability affects unauthenticated remote attack...

CVE-2025-3125

MEDIUM CVSS 6.7 Nov 5, 2025

An arbitrary file upload vulnerability in WSO2 products allows authenticated admin users to upload malicious files to server locations they control, potentially leading to remote code execution. This ...

CVE-2025-5605

MEDIUM CVSS 4.3 Oct 24, 2025

An authentication bypass vulnerability in WSO2 Management Console allows attackers with console access to manipulate request URIs and access restricted resources, leading to partial information disclo...

CVE-2025-5350

MEDIUM CVSS 5.9 Oct 24, 2025

This vulnerability allows attackers to perform SSRF attacks and execute reflected XSS in WSO2 products through the deprecated Try-It feature. Only administrative users are affected, as exploitation re...

CVE-2025-9955

MEDIUM CVSS 5.7 Oct 16, 2025

An improper access control vulnerability in WSO2 Enterprise Integrator allows low-privileged users to access internal SOAP admin services for system logs and user-store configuration. This exposes ope...

CVE-2024-3511

MEDIUM CVSS 4.3 Jun 23, 2025

This CVE describes an authorization bypass vulnerability in WSO2 products that allows authenticated users with management console access to retrieve versioned registry files without proper permissions...

CVE-2024-8008

MEDIUM CVSS 5.2 Jun 2, 2025

A reflected XSS vulnerability in WSO2 products allows attackers to inject malicious JavaScript via JDBC user store connection validation error messages. This affects users of vulnerable WSO2 products,...

CVE-2024-0392

MEDIUM CVSS 5.4 Feb 27, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in WSO2 Enterprise Integrator 6.6.0 management console allows attackers to trick authenticated users into performing unauthorized state-changing opera...