Junglewise Threat Intelligence

CVE-2022-29464: WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

CVE-2022-29464 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-25

Technologies: Wso2 API Manager, Wso2 Identity Server as Key Manager, Wso2 Enterprise Integrator, Wso2 Identity Server, Apple Multiple Products, Wso2 Open Banking AM. Vendors: Wso2, Apple.

Executive brief

Multiple WSO2 products are vulnerable to unrestricted file upload via the /fileupload endpoint. By using a directory traversal sequence in the Content-Disposition header, an unauthenticated attacker can upload malicious files to the web root, leading to remote code execution.

Affected products

  • WSO2 API Manager 2.2.0 up to 4.0.0
  • WSO2 Identity Server 5.2.0 up to 5.11.0
  • WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, 5.6.0
  • WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0
  • WSO2 Enterprise Integrator 6.2.0 up to 6.6.0
  • WSO2 Open Banking AM 1.4.0 up to 2.0.0
  • WSO2 Open Banking KM 1.4.0 up to 2.0.0

Timeline

  • 2022-04-22: disclosed: Mailing list disclosure
  • 2022-04-25: advisory: NVD publication date
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats