Arbitrary file upload in WSO2 Inc. products - CVE-2024-7074

 

Arbitrary file upload in WSO2 Inc. products - CVE-2024-7074

Published: January 6, 2025


Vulnerability identifier: #VU102299
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7074
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload within the SynapseArtifactUploaderAdmin endpoint. A remote administrator can upload a malicious file and execute it on the server.


Affected software

WSO2 Open Banking AM
WSO2 Open banking KM
WSO2 Open Banking IAM
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager

How to mitigate CVE-2024-7074

Install updates from vendor's website.


External References

Related Security Bulletins