A significant vulnerability in WSO2 API Manager has been actively exploited in the wild, as revealed by watchTowr's findings This article explores vulnerability wso2 api. .
They have also been released for WSO2 Support Subscription Holders with the following update levels: WSO2 API Control Plane 4.6.0 - Update level 22; WSO2 API Control Plane 4.5.0 - Update level 58; WSO2 API Manager 4.6.0 - Update level 21; WSO2 API Manager 4.5.0 - Update level 57; WSO2 API Manager 4.4.0 - Update level 72; WSO2 API Manager 4.3.0 - Update level 108; WSO2 API Manager 4.2.0 - Update level 197; WSO2 API Manager 4.1.0 - Update level 257; WSO2 Traffic Manager 4.6.0 - Update level 21; WSO2 Traffic Manager 4.5.0 - Update level 56; WSO2 Universal Gateway 4.6.0 - Update level 21; WSO2 Universal Gateway 4.5.0 - Update level 57.
During observed attacks, the forged JWT token is suspected to be used to gain unauthorized access to every API backend endpoint, credentials, consumer keys, and secrets for all registered applications, Ganchev noted.











