#VU102299 Arbitrary file upload in WSO2 Inc. products - CVE-2024-7074
Published: January 6, 2025
Vulnerability identifier: #VU102299
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-7074
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2 Open banking KM
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2 Open banking KM
Software vendor:
WSO2 Inc.
WSO2 Inc.
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the SynapseArtifactUploaderAdmin endpoint. A remote administrator can upload a malicious file and execute it on the server.
Remediation
Install updates from vendor's website.