Arbitrary file upload in WSO2 Inc. products - CVE-2022-29464
Published: April 27, 2022 / Updated: June 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of files during file upload at the /fileupload endpoint. A remote non-authenticated attacker can upload a malicious file with a Content-Disposition directory traversal sequence to place it under the webroot directory and execute it on the server.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Affected software
Open Banking AM
WSO2 Identity Server as Key Manager
WSO2 Enterprise Integrator
WSO2 API Manager
WSO2 Identity Server Analytics
WSO2 Identity Server
How to mitigate CVE-2022-29464
Links to Public Exploits and PoC-codes
- Exploit #10085 - CVE-2022-29464 (CVE-2022-29464 exploit script) (June 21, 2024)
- Exploit #9007 - CVE-2022-29464 (Perform With Mass Exploits In WSO Management.) (April 26, 2023)
- Exploit #8731 - CVE-2022-29464-mass () (January 11, 2023)
- Exploit #8610 - CVE-2022-29464 (RCE exploit for WSO2) (November 15, 2022)
- Exploit #8389 - CVE-2022-29464 (WSO2 Arbitrary File Upload to Remote Command Execution (RCE)) (September 22, 2022)
- Exploit #8199 - -CVE-2022-29464 () (August 1, 2022)
- Exploit #8112 - WSO2RCE (CVE-2022-29464 Exploit) (July 5, 2022)
- Exploit #8070 - Mass-exploit-CVE-2022-29464 (Mass Exploit for CVE 2022-29464 on Carbon) (June 23, 2022)
- Exploit #7979 - Better-CVE-2022-29464 (CVE-2022-29464 PoC for WSO2 products) (June 6, 2022)
- Exploit #7900 - CVE-2022-29464-mass () (May 27, 2022)
- Exploit #7871 - CVE-2022-29464 () (May 23, 2022)
- Exploit #7836 - CVE-2022-29464-loader (A bots loader for CVE-2022-29464 with multithreading) (May 16, 2022)
- Exploit #7774 - WSO2 Arbitrary File Upload to RCE (May 12, 2022)
- Exploit #7722 - CVE-2022-29464 (cve-2022-29464 EXP) (May 8, 2022)
- Exploit #7718 - CVE-2022-29464 (1) (May 5, 2022)
- Exploit #7717 - WSO Arbitrary File Upload / Remote Code Execution (May 4, 2022)
- Exploit #7710 - CVE-2022-29464 (CVE-2022-29464 POC exploit) (May 1, 2022)
- Exploit #7708 - CVE-2022-29464 (CVE-2022-29464) (May 1, 2022)
- Exploit #7705 - WSO2--CVE-2022-29464 (Pre-auth RCE bug CVE-2022-29464) (April 27, 2022)
- Exploit #7704 - wso2-rce-cve-2022-29464 () (April 27, 2022)
- Exploit #7703 - CVE-2022-29464 () (April 27, 2022)
- Exploit #7702 - cve-2022-29464 (cve-2022-29464 批量脚本) (April 27, 2022)
- Exploit #7701 - CVE-2022-29464 (WSO2 RCE (CVE-2022-29464) exploit and writeup.) (April 27, 2022)
- Exploit #7700 - WSOB (? WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.) (April 27, 2022)
- Exploit #7699 - cve-2022-29464 () (April 27, 2022)
- Exploit #7698 - WSO2-CVE-2022-29464 (Pre-auth RCE bug CVE-2022-29464) (April 27, 2022)
- Exploit #7697 - cve-2022-29464 (cve-2022-29464 批量脚本) (April 27, 2022)
- Exploit #7696 - nmap-CVE-2022-29464 ( Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.) (April 27, 2022)
- Exploit #7695 - CVE-2022-29464 (WSO2 RCE (CVE-2022-29464) ) (April 27, 2022)
- Exploit #7694 - CVE-2022-29464 () (April 27, 2022)