📦 Open Banking Km

by Wso2

🔍 What is Open Banking Km?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-9312

CRITICAL CVSS 9.8 Nov 18, 2025

A missing authentication enforcement vulnerability in WSO2 products allows unauthenticated access to System REST APIs and SOAP services when mutual TLS (mTLS) is enabled in certain default configurati...

CVE-2025-10611

CRITICAL CVSS 9.8 Oct 16, 2025

This critical vulnerability in WSO2 products allows attackers to bypass authentication and authorization checks for certain REST APIs, enabling unauthenticated administrative access. Attackers could p...

CVE-2024-6914

CRITICAL CVSS 9.8 May 22, 2025

This vulnerability allows attackers to reset any user's password via a flawed SOAP admin service in WSO2 products, leading to complete account takeover including privileged accounts. It affects WSO2 p...

CVE-2022-29464

CRITICAL CVSS 9.8 Apr 18, 2022

CVE-2022-29464 is a critical unrestricted file upload vulnerability in multiple WSO2 products that allows attackers to upload malicious files to web-accessible directories via directory traversal. Thi...

CVE-2024-7073

MEDIUM CVSS 6.5 Jun 2, 2025

This CVE describes a server-side request forgery (SSRF) vulnerability in multiple WSO2 products that allows unauthenticated attackers to manipulate server-side requests. Attackers can access internal ...

CVE-2024-7097

MEDIUM CVSS 4.3 May 30, 2025

This vulnerability allows attackers to create unauthorized user accounts in WSO2 products regardless of self-registration settings. It affects WSO2 products with SOAP admin service enabled. Attackers ...