Cyber Resilience

CVE-2024-4598

Wso2 Api Manager 3.2.0 – 3.2.0.422

Published
23 September 2025
Modified
09 January 2026
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0030 22th percentile
Risk Priority 49 floored blend · peak EPSS

Summary

CVE-2024-4598 is a medium-severity Improper Restriction of Security Token Assignment (CWE-1259) vulnerability in Wso2 Api Manager. Its CVSS base score is 6.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Access Token Manipulation (T1134); ranked at the 22th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-25 (Reference Monitor) and AC-3 (Access Enforcement) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or…

more

cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1134 Access Token Manipulation Stealth
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
T1134.001 Token Impersonation/Theft Stealth
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-6839Same product: Wso2 Api Manager
CVE-2026-2053Same product: Wso2 Api Manager
CVE-2024-4867Same product: Wso2 Api Manager
CVE-2024-10242Same product: Wso2 Api Manager
CVE-2025-2905Same product: Wso2 Api Manager
CVE-2023-31664Same product: Wso2 Api Manager
CVE-2024-5848Same product: Wso2 Api Manager
CVE-2024-8010Same product: Wso2 Api Manager
CVE-2024-1524Same product: Wso2 Api Manager
CVE-2023-6835Same product: Wso2 Api Manager

Affected Assets

wso2
api manager
3.2.0 — 3.2.0.422 · 3.2.1 — 3.2.1.42 · 4.1.0 — 4.1.0.152
wso2
micro integrator
1.2.0 — 1.2.0.157 · 4.1.0 — 4.1.0.95

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

A tamperproof reference monitor ensures security tokens cannot be improperly assigned or altered outside policy.

Access enforcement directly requires that security tokens used for authorization decisions are protected from unauthorized assignment or modification.

Isolating security functions from non-security functions reduces the attack surface for tampering with token assignment logic.

Security attributes (tokens) must be associated and maintained with subjects/objects, which structurally prevents improper assignment or lack of protection.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-05 mostly match
prevents

Proper definition and enforcement of authorizations directly addresses improper security token restrictions.

ID.RA-09 partial match
prevents

Pre-acquisition hardware integrity checks can detect flawed token protection mechanisms before deployment.

PR.IR-01 partial match
prevents

Logical access protections can prevent exploitation of improperly assigned hardware security tokens.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Privileged access rights help ensure only authorized processes can assign or modify tokens.

finds

Security testing can detect improper token assignment but does not prevent it at design time.

prevents

Information access restriction directly limits which entities can obtain or use security tokens.

prevents

Secure architecture principles can guide token protection mechanisms but do not enforce assignment rules.

prevents

Secure coding practices reduce the likelihood of token-assignment bugs but do not define the policy.

none

Cryptography can protect token confidentiality but does not address improper assignment logic.

References