This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
Project Subscriptions
No advisories yet.
Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/#solution
Workaround
No workaround given by the vendor.
Fri, 07 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wso2 micro Integrator
|
|
| Vendors & Products |
Wso2 micro Integrator
|
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products. | |
| Title | Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products | |
| First Time appeared |
Wso2
Wso2 wso2-synapse Wso2 wso2 Api Manager Wso2 wso2 Enterprise Integrator Wso2 wso2 Micro Integrator |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:wso2:wso2-synapse:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_micro_integrator:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2-synapse Wso2 wso2 Api Manager Wso2 wso2 Enterprise Integrator Wso2 wso2 Micro Integrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-08-07T17:45:43.395Z
Reserved: 2024-07-08T09:20:26.394Z
Link: CVE-2024-6541
Updated: 2026-08-07T17:45:37.776Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T09:59:13Z