Executive brief
Multiple WSO2 products are vulnerable to unrestricted file upload via the /fileupload endpoint. By using a directory traversal sequence in the Content-Disposition header, an unauthenticated attacker can upload malicious files to the web root, leading to remote code execution.
Affected products
- WSO2 API Manager 2.2.0 up to 4.0.0
- WSO2 Identity Server 5.2.0 up to 5.11.0
- WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, 5.6.0
- WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0
- WSO2 Enterprise Integrator 6.2.0 up to 6.6.0
- WSO2 Open Banking AM 1.4.0 up to 2.0.0
- WSO2 Open Banking KM 1.4.0 up to 2.0.0
Timeline
- 2022-04-22: disclosed: Mailing list disclosure
- 2022-04-25: advisory: NVD publication date
- 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog