An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.
History

Mon, 29 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 enterprise Integrator
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Iam
Vendors & Products Wso2
Wso2 enterprise Integrator
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Iam

Fri, 26 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.
Title Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code Execution
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published: 2025-09-26T08:18:21.708Z

Updated: 2025-09-29T12:38:07.003Z

Reserved: 2025-03-03T04:53:13.295Z

Link: CVE-2025-1862

cve-icon Vulnrichment

Updated: 2025-09-29T12:38:04.225Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-26T09:15:31.687

Modified: 2025-09-26T14:32:19.853

Link: CVE-2025-1862

cve-icon Redhat

No data.