← Back

CVE-2022-29464

Published: Apr 18, 2022Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

Affected (11)

8 products
Api Manager
Enterprise Integrator
Identity Server
Identity Server Analytics
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
From 2.2.0 to 4.0.0
From 6.2.0 to 6.6.0
From 5.2.0 to 5.11.0
Wso2
Version 5.4.0
Version 5.4.1
Version 5.5.0
Version 5.6.0
From 5.3.0 to 5.10.0
From 1.3.0 to 2.0.0
Version 2.0.0
From 1.3.0 to 1.5.0

References (9)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.