Arbitrary file upload in WSO2 Inc. products - CVE-2024-7074
Published: January 6, 2025
Vulnerability identifier: #VU102299
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7074
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the SynapseArtifactUploaderAdmin endpoint. A remote administrator can upload a malicious file and execute it on the server.
Affected software
WSO2 Open Banking AM
WSO2 Open banking KM
WSO2 Open Banking IAM
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open banking KM
WSO2 Open Banking IAM
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
How to mitigate CVE-2024-7074
Install updates from vendor's website.