{"api_version":"v1","generated_at":"2026-10-09T16:55:00+00:00","product":{"cve_count":5,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-wso2-wso2-identity-server-as-key-manager-b69514e76c1e","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"WSO2 Identity Server as Key Manager","next_cursor":null,"observations":[{"affected":"WSO2 Identity Server as Key Manager: < 5.10.0, 5.10.0 < 5.10.0.371; WSO2 Identity Server: < 5.10.0, 5.10.0 < 5.10.0.380, 5.11.0 < 5.11.0.427, 6.0.0 < 6.0.0.254, 6.1.0 < 6.1.0.255, 7.0.0 < 7.0.0.132, 7.1.0 < 7.1.0.40, 7.2.0 < 7.2.0.2; WSO2 Open Banking AM: < 2.0.0, 2.0.0 < 2.0.0.400; WSO2 API Manager: < 3.1.0, 3.1.0 < 3.1.0.351, 3.2.0 < 3.2.0.455, 4.0.0 < 4.0.0.375; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.420","affected_versions_present":true,"cve_id":"CVE-2025-13736","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13736","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/#solution","last_modified":"2026-08-06T12:35:37.283Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/","primary_source":"","published":"2026-08-06T07:33:03.994Z"},{"affected":"WSO2 Identity Server as Key Manager: < 5.3.0, 5.3.0 < 5.3.0.41, 5.5.0 < 5.5.0.53, 5.6.0 < 5.6.0.75, 5.7.0 < 5.7.0.125, 5.9.0 < 5.9.0.176, 5.10.0 < 5.10.0.359; WSO2 Identity Server: < 5.2.0, 5.2.0 < 5.2.0.34, 5.3.0 < 5.3.0.36, 5.4.0 < 5.4.0.34, 5.4.1 < 5.4.1.38, 5.5.0 < 5.5.0.52, 5.6.0 < 5.6.0.60, 5.7.0 < 5.7.0.126, 5.8.0 < 5.8.0.110, 5.9.0 < 5.9.0.169, 5.10.0 < 5.10.0.369, 5.11.0 < 5.11.0.413, 6.0.0 < 6.0.0.244, 6.1.0 < 6.1.0.243, 7.0.0 < 7.0.0.118, 7.1.0 < 7.1.0.25; WSO2 Open Banking KM: < 1.4.0, 1.4.0 < 1.4.0.133, 1.5.0 < 1.5.0.123; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.409; WSO2 Open Banking AM: < 1.4.0, 1.4.0 < 1.4.0.139, 1.5.0 < 1.5.0.140, 2.0.0 < 2.0.0.389; WSO2 API Manager: < 2.0.0, 2.0.0 < 2.0.0.31, 2.1.0 < 2.1.0.40, 2.2.0 < 2.2.0.59, 2.5.0 < 2.5.0.85, 2.6.0 < 2.6.0.146, 3.0.0 < 3.0.0.176, 3.1.0 < 3.1.0.340, 3.2.0 < 3.2.0.441, 3.2.1 < 3.2.1.61, 4.0.0 < 4.0.0.361, 4.1.0 < 4.1.0.224, 4.2.0 < 4.2.0.162, 4.3.0 < 4.3.0.75, 4.4.0 < 4.4.0.39, 4.5.0 < 4.5.0.23; WSO2 Identity Server Analytics: < 5.2.0, 5.2.0 < 5.2.0.19, 5.3.0 < 5.3.0.17, 5.5.0 < 5.5.0.31, 5.6.0 < 5.6.0.38; API Manager Analytics: < 2.0.0, 2.0.0 < 2.0.0.14, 2.1.0 < 2.1.0.19, 2.2.0 < 2.2.0.30, 2.5.0 < 2.5.0.39; WSO2 Enterprise Integrator: < 6.2.0, 6.2.0 < 6.2.0.62, 6.3.0 < 6.3.0.70; WSO2 Enterprise Service Bus Analytics: < 5.0.0, 5.0.0 < 5.0.0.13; WSO2 Data Analytics Server: < 3.1.0, 3.1.0 < 3.1.0.20, 3.2.0 < 3.2.0.33; WSO2 Enterprise Mobility Manager: < 2.2.0, 2.2.0 < 2.2.0.28; WSO2 Universal Gateway: 4.5.0 < 4.5.0.22; WSO2 API Control Plane: 4.5.0 < 4.5.0.24; WSO2 Traffic Manager: 4.5.0 < 4.5.0.22; org.wso2.carbon.extension.identity.authenticator.outbound.totp:org.wso2.carbon.extension.identity.authenticator.totp.connector: 2.0.10 < 2.0.10.1, 2.0.15 < 2.0.15.1, 2.0.21 < 2.0.21.1, 2.0.22 < 2.0.22.1, 2.1.12 < 2.1.12.1, 2.1 < 2.1.1972, 2.2 < 2.2.24, 2.2 < 2.2.25, 3.1.0 < 3.1.0.74, 3.3.6 < 3.3.6.7, 3.3.26 < 3.3.26.2, 3.3.35 < 3.3.35.1; org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util: 6.7.206 < 6.7.206.567, 6.7.210 < 6.7.210.63, 9.0.174 < 9.0.174.522, 9.20.74 < 9.20.74.379, 9.28.116 < 9.28.116.360, 9.29.120 < 9.29.120.184, 9.30.67 < 9.30.67.109, 9.31.86 < 9.31.86.71; org.wso2.carbon:org.wso2.carbon.base: 4.4.7 < 4.4.7.6, 4.4.9 < 4.4.9.11, 4.4.11 < 4.4.11.9, 4.4.26 < 4.4.26.12, 4.4.35 < 4.4.35.44, 4.5.1 < 4.5.1.43, 4.6.0 < 4.6.0.1990, 4.6.1 < 4.6.1.149, 4.6.2 < 4.6.2.667, 4.6.3 < 4.6.3.36, 4.6.4 < 4.6.4.14, 4.7.1 < 4.7.1.68, 4.8.1 < 4.8.1.39, 4.9.0 < 4.9.0.99, 4.9.26 < 4.9.26.25, 4.9.27 < 4.9.27.10, 4.9.28 < 4.9.28.11, 4.10.9 < 4.10.9.66, 4.10.42 < 4.10.42.9, 4.9 < 4.9.29, 4.10 < 4.10.94; org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.mgt: 5.2.0 < 5.2.0.4, 5.2.2 < 5.2.2.21, 5.7.5 < 5.7.5.18, 5.11.148 < 5.11.148.19, 5.11.256 < 5.11.256.21, 5.12.153 < 5.12.153.63, 5.12.387 < 5.12.387.46, 5.14.97 < 5.14.97.89, 5.17.5 < 5.17.5.317, 5.17.118 < 5.17.118.17, 5.18.187 < 5.18.187.309, 5.18.248 < 5.18.248.30, 5.23.8 < 5.23.8.207, 5.24.8 < 5.24.8.23, 5.25.92 < 5.25.92.152, 5.25.705 < 5.25.705.19, 5.25.713 < 5.25.713.9, 5.25.724 < 5.25.724.3, 7.0.78 < 7.0.78.133, 7.8.23 < 7.8.23.47, 5.25 < 5.25.734; org.wso2.carbon:org.wso2.carbon.server.admin: 4.4.7 < 4.4.7.6, 4.4.9 < 4.4.9.11, 4.4.11 < 4.4.11.9, 4.4.26 < 4.4.26.12, 4.4.32 < 4.4.32.16, 4.4.35 < 4.4.35.44, 4.5.1 < 4.5.1.43, 4.6.0 < 4.6.0.1990, 4.6.1 < 4.6.1.149, 4.6.2 < 4.6.2.667, 4.6.3 < 4.6.3.36, 4.6.4 < 4.6.4.14, 4.7.1 < 4.7.1.68, 4.8.1 < 4.8.1.39, 4.9.0 < 4.9.0.99, 4.9.26 < 4.9.26.25, 4.9.27 < 4.9.27.10, 4.9.28 < 4.9.28.11, 4.10.9 < 4.10.9.66, 4.10.42 < 4.10.42.9, 4.9 < 4.9.29, 4.10 < 4.10.94; org.wso2.carbon.identity.workflow.user:org.wso2.carbon.user.mgt.workflow: 5.1.1 < 5.1.1.1, 5.1.2 < 5.1.2.1, 5.1.5 < 5.1.5.1, 5.3.3 < 5.3.3.1, 5.4.0 < 5.4.0.4, 5.4.1 < 5.4.1.5, 5.6.0 < 5.6.0.1","affected_versions_present":true,"cve_id":"CVE-2025-9804","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-9804","fixed":"org.wso2.carbon.extension.identity.authenticator.outbound.totp:org.wso2.carbon.extension.identity.authenticator.totp.connector: 3.3.41 \u2264 *; org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util: 9.32.133 \u2264 *; org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.mgt: 7.8.489 \u2264 *; org.wso2.carbon.identity.workflow.user:org.wso2.carbon.user.mgt.workflow: 5.6.21 \u2264 *","last_modified":"2025-10-17T16:01:25.350Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/","primary_source":"","published":"2025-10-16T12:33:45.426Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.338; 5.10.0 < 5.10.0.345; 5.11.0 < 5.11.0.394; 2.0.0 < 2.0.0.389","affected_versions_present":true,"cve_id":"CVE-2025-0672","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-0672","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-25T16:01:00.676Z","patch_url":"","primary_source":"","published":"2025-09-23T17:30:42.687Z"},{"affected":"5.10.0 < 5.10.0.338; < 3.2.0; 3.2.0 < 3.2.0.409; 3.2.1 < 3.2.1.33; 4.0.0 < 4.0.0.327; 4.1.0 < 4.1.0.188; 4.2.0 < 4.2.0.128; 4.3.0 < 4.3.0.38","affected_versions_present":true,"cve_id":"CVE-2024-6429","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-6429","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-25T16:14:02.884Z","patch_url":"","primary_source":"","published":"2025-09-23T16:37:58.340Z"},{"affected":"< 5.3.0; 5.3.0 < 5.3.0.37; 5.5.0 < 5.5.0.50; 5.6.0 < 5.6.0.71; 5.7.0 < 5.7.0.122; 5.9.0 < 5.9.0.165; 5.10.0 < 5.10.0.312; < 5.2.0","affected_versions_present":true,"cve_id":"CVE-2024-7073","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-7073","fixed":"7.4.3 \u2264 *","last_modified":"2025-06-02T17:06:05.767Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3562","primary_source":"","published":"2025-06-02T16:38:33.113Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"WSO2"}}
