← Back

CVE-2024-7487

nvd nist
Published: May 22, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

Affected (1)

1 product
Identity Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0.0

References (1)

Timeline

No history available yet.