Arbitrary file upload in WSO2 Inc. products - CVE-2024-7074
Published: January 6, 2025
Vulnerability identifier: #VU102299
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-7074
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: WSO2 Inc.
Affected software:
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2 Open banking KM
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2 Open banking KM
Detailed vulnerability description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the SynapseArtifactUploaderAdmin endpoint. A remote administrator can upload a malicious file and execute it on the server.
How to mitigate CVE-2024-7074
Install updates from vendor's website.