← Back

CVE-2024-8995

nvd nist
Published: Aug 6, 2026Modified: Aug 13, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.7
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Affected (23)

8 products
Api Control Plane
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Traffic Manager
Universal Gateway
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.56
From 4.6.0 to 4.6.0.20
Wso2
From 3.1.0 to 3.1.0.320
From 3.2.0 to 3.2.0.413
From 3.2.1 to 3.2.1.90
From 4.0.0 to 4.0.0.334
From 4.1.0 to 4.1.0.255
From 4.2.0 to 4.2.0.195
From 4.3.0 to 4.3.0.106
From 4.4.0 to 4.4.0.70
From 4.5.0 to 4.5.0.55
From 4.6.0 to 4.6.0.19
Wso2
From 5.10.0 to 5.10.0.338
From 5.11.0 to 5.11.0.395
From 6.0.0 to 6.0.0.229
From 6.1.0 to 6.1.0.208
From 5.10.0 to 5.10.0.338
From 2.0.0 to 2.0.0.369
From 2.0.0 to 2.0.0.389
Wso2
From 4.5.0 to 4.5.0.54
From 4.6.0 to 4.6.0.19
Wso2
From 4.5.0 to 4.5.0.55
From 4.6.0 to 4.6.0.19

References (1)

Timeline

No history available yet.