All the vulnerabilites related to WSO2 - WSO2 Enterprise Mobility Manager
cve-2024-7074
Vulnerability from cvelistv5
Published
2025-06-02 16:42
Modified
2025-06-02 17:05
Severity ?
EPSS score ?
Summary
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remote Code Execution
References
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-7074", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-06-02T17:04:40.480620Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-06-02T17:05:49.920Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "WSO2 Enterprise Integrator", "vendor": "WSO2", "versions": [ { "lessThan": "6.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "6.0.0.21", "status": "affected", "version": "6.0.0", "versionType": "custom" }, { "lessThan": "6.1.0.38", "status": "affected", "version": "6.1.0", "versionType": "custom" }, { "lessThan": "6.1.1.42", "status": "affected", "version": "6.1.1", "versionType": "custom" }, { "lessThan": "6.2.0.61", "status": "affected", "version": "6.2.0", "versionType": "custom" }, { "lessThan": "6.3.0.69", "status": "affected", "version": "6.3.0", "versionType": "custom" }, { "lessThan": "6.4.0.96", "status": "affected", "version": "6.4.0", "versionType": "custom" }, { "lessThan": "6.5.0.102", "status": "affected", "version": "6.5.0", "versionType": "custom" }, { "lessThan": "6.6.0.198", "status": "affected", "version": "6.6.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 API Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "2.0.0.28", "status": "affected", "version": "2.0.0", "versionType": "custom" }, { "lessThan": "2.1.0.38", "status": "affected", "version": "2.1.0", "versionType": "custom" }, { "lessThan": "2.2.0.57", "status": "affected", "version": "2.2.0", "versionType": "custom" }, { "lessThan": "2.5.0.83", "status": "affected", "version": "2.5.0", "versionType": "custom" }, { "lessThan": "2.6.0.143", "status": "affected", "version": "2.6.0", "versionType": "custom" }, { "lessThan": "3.0.0.162", "status": "affected", "version": "3.0.0", "versionType": "custom" }, { "lessThan": "3.1.0.293", "status": "affected", "version": "3.1.0", "versionType": "custom" }, { "lessThan": "3.2.0.384", "status": "affected", "version": "3.2.0", "versionType": "custom" }, { "lessThan": "3.2.1.16", "status": "affected", "version": "3.2.1", "versionType": "custom" }, { "lessThan": "4.0.0.305", "status": "affected", "version": "4.0.0", "versionType": "custom" }, { "lessThan": "4.1.0.166", "status": "affected", "version": "4.1.0", "versionType": "custom" }, { "lessThan": "4.2.0.100", "status": "affected", "version": "4.2.0", "versionType": "custom" }, { "lessThan": "4.3.0.16", "status": "affected", "version": "4.3.0", "versionType": "custom" } ] }, { "defaultStatus": "unknown", "product": "WSO2 Enterprise Service Bus", "vendor": "WSO2", "versions": [ { "lessThan": "4.9.0.10", "status": "affected", "version": "4.9.0", "versionType": "custom" }, { "lessThan": "5.0.0.28", "status": "affected", "version": "5.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unknown", "product": "WSO2 Enterprise Mobility Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.2.0.27", "status": "affected", "version": "2.2.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Micro Integrator", "vendor": "WSO2", "versions": [ { "lessThan": "1.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.0.0.49", "status": "affected", "version": "1.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Open Banking AM", "vendor": "WSO2", "versions": [ { "lessThan": "1.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.3.0.132", "status": "affected", "version": "1.3.0", "versionType": "custom" }, { "lessThan": "1.4.0.135", "status": "affected", "version": "1.4.0", "versionType": "custom" }, { "lessThan": "1.5.0.137", "status": "affected", "version": "1.5.0", "versionType": "custom" }, { "lessThan": "2.0.0.342", "status": "affected", "version": "2.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unknown", "packageName": "org.wso2.carbon.mediation:org.wso2.carbon.mediation.artifactuploader", "product": "WSO2 Carbon Synapse Artifact Uploader BE", "vendor": "WSO2", "versions": [ { "lessThan": "4.4.10.3", "status": "affected", "version": "4.4.10", "versionType": "custom" }, { "lessThan": "4.6.1.4", "status": "affected", "version": "4.6.1", "versionType": "custom" }, { "lessThan": "4.6.6.9", "status": "affected", "version": "4.6.6", "versionType": "custom" }, { "lessThan": "4.6.10.4", "status": "affected", "version": "4.6.10", "versionType": "custom" }, { "lessThan": "4.6.16.2", "status": "affected", "version": "4.6.16", "versionType": "custom" }, { "lessThan": "4.6.19.10", "status": "affected", "version": "4.6.19", "versionType": "custom" }, { "lessThan": "4.6.64.2", "status": "affected", "version": "4.6.64", "versionType": "custom" }, { "lessThan": "4.6.67.15", "status": "affected", "version": "4.6.67", "versionType": "custom" }, { "lessThan": "4.6.89.12", "status": "affected", "version": "4.6.89", "versionType": "custom" }, { "lessThan": "4.6.105.59", "status": "affected", "version": "4.6.105", "versionType": "custom" }, { "lessThan": "4.6.150.11", "status": "affected", "version": "4.6.150", "versionType": "custom" }, { "lessThan": "4.7.20.5", "status": "affected", "version": "4.7.20", "versionType": "custom" }, { "lessThan": "4.7.30.42", "status": "affected", "version": "4.7.30", "versionType": "custom" }, { "lessThan": "4.7.35.5", "status": "affected", "version": "4.7.35", "versionType": "custom" }, { "lessThan": "4.7.61.56", "status": "affected", "version": "4.7.61", "versionType": "custom" }, { "lessThan": "4.7.99.299", "status": "affected", "version": "4.7.99", "versionType": "custom" }, { "lessThan": "4.7.131.15", "status": "affected", "version": "4.7.131", "versionType": "custom" }, { "lessThan": "4.7.175.18", "status": "affected", "version": "4.7.175", "versionType": "custom" }, { "lessThan": "4.7.188.5", "status": "affected", "version": "4.7.188", "versionType": "custom" }, { "lessThan": "4.7.204.5", "status": "affected", "version": "4.7.204", "versionType": "custom" }, { "lessThanOrEqual": "*", "status": "unaffected", "version": "4.7.216", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Anonymous working with Trend Micro Zero Day Initiative" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server.\u003cbr\u003e\u003cbr\u003eBy leveraging this vulnerability, an attacker could upload a specially crafted payload, potentially achieving remote code execution (RCE) on the server. Exploitation requires valid admin credentials, limiting its impact to authorized but potentially malicious users.\u003cbr\u003e" } ], "value": "An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server.\n\nBy leveraging this vulnerability, an attacker could upload a specially crafted payload, potentially achieving remote code execution (RCE) on the server. Exploitation requires valid admin credentials, limiting its impact to authorized but potentially malicious users." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-434", "description": "CWE-434 Unrestricted Upload of File with Dangerous Type", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-06-02T16:42:19.264Z", "orgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "shortName": "WSO2" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3566/" } ], "solutions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Follow the instructions given on \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3566/#solution\"\u003ehttps://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3...\u003c/a\u003e \u003cbr\u003e\u003cbr\u003e" } ], "value": "Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3566/#solution" } ], "source": { "advisory": "WSO2-2024-3566", "discovery": "EXTERNAL" }, "title": "Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remote Code Execution", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "assignerShortName": "WSO2", "cveId": "CVE-2024-7074", "datePublished": "2025-06-02T16:42:19.264Z", "dateReserved": "2024-07-24T12:15:52.796Z", "dateUpdated": "2025-06-02T17:05:49.920Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-7096
Vulnerability from cvelistv5
Published
2025-05-30 14:54
Modified
2025-05-30 15:01
Severity ?
EPSS score ?
Summary
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
References
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-7096", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-05-30T15:01:23.580052Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-05-30T15:01:40.977Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "WSO2 Open Banking IAM", "vendor": "WSO2", "versions": [ { "lessThan": "2.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "2.0.0.364", "status": "affected", "version": "2.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Open Banking AM", "vendor": "WSO2", "versions": [ { "lessThan": "1.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.3.0.131", "status": "affected", "version": "1.3.0", "versionType": "custom" }, { "lessThan": "1.4.0.134", "status": "affected", "version": "1.4.0", "versionType": "custom" }, { "lessThan": "1.5.0.136", "status": "affected", "version": "1.5.0", "versionType": "custom" }, { "lessThan": "2.0.0.343", "status": "affected", "version": "2.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 API Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "2.0.0.29", "status": "affected", "version": "2.0.0", "versionType": "custom" }, { "lessThan": "2.1.0.39", "status": "affected", "version": "2.1.0", "versionType": "custom" }, { "lessThan": "2.2.0.56", "status": "affected", "version": "2.2.0", "versionType": "custom" }, { "lessThan": "2.5.0.83", "status": "affected", "version": "2.5.0", "versionType": "custom" }, { "lessThan": "2.6.0.142", "status": "affected", "version": "2.6.0", "versionType": "custom" }, { "lessThan": "3.0.0.162", "status": "affected", "version": "3.0.0", "versionType": "custom" }, { "lessThan": "3.1.0.294", "status": "affected", "version": "3.1.0", "versionType": "custom" }, { "lessThan": "3.2.0.384", "status": "affected", "version": "3.2.0", "versionType": "custom" }, { "lessThan": "3.2.1.16", "status": "affected", "version": "3.2.1", "versionType": "custom" }, { "lessThan": "4.0.0.305", "status": "affected", "version": "4.0.0", "versionType": "custom" }, { "lessThan": "4.1.0.166", "status": "affected", "version": "4.1.0", "versionType": "custom" }, { "lessThan": "4.2.0.101", "status": "affected", "version": "4.2.0", "versionType": "custom" }, { "lessThan": "4.3.0.16", "status": "affected", "version": "4.3.0", "versionType": "custom" } ] }, { "defaultStatus": "unknown", "product": "WSO2 Enterprise Mobility Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.2.0.26", "status": "affected", "version": "2.2.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Identity Server", "vendor": "WSO2", "versions": [ { "lessThan": "5.2.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "5.2.0.32", "status": "affected", "version": "5.2.0", "versionType": "custom" }, { "lessThan": "5.3.0.33", "status": "affected", "version": "5.3.0", "versionType": "custom" }, { "lessThan": "5.4.1.36", "status": "affected", "version": "5.4.1", "versionType": "custom" }, { "lessThan": "5.5.0.50", "status": "affected", "version": "5.5.0", "versionType": "custom" }, { "lessThan": "5.6.0.58", "status": "affected", "version": "5.6.0", "versionType": "custom" }, { "lessThan": "5.7.0.123", "status": "affected", "version": "5.7.0", "versionType": "custom" }, { "lessThan": "5.8.0.106", "status": "affected", "version": "5.8.0", "versionType": "custom" }, { "lessThan": "5.9.0.157", "status": "affected", "version": "5.9.0", "versionType": "custom" }, { "lessThan": "5.10.0.318", "status": "affected", "version": "5.10.0", "versionType": "custom" }, { "lessThan": "5.11.0.365", "status": "affected", "version": "5.11.0", "versionType": "custom" }, { "lessThan": "6.0.0.209", "status": "affected", "version": "6.0.0", "versionType": "custom" }, { "lessThan": "6.1.0.188", "status": "affected", "version": "6.1.0", "versionType": "custom" }, { "lessThan": "7.0.0.60", "status": "affected", "version": "7.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Identity Server as Key Manager", "vendor": "WSO2", "versions": [ { "lessThan": "5.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "5.3.0.38", "status": "affected", "version": "5.3.0", "versionType": "custom" }, { "lessThan": "5.5.0.51", "status": "affected", "version": "5.5.0", "versionType": "custom" }, { "lessThan": "5.6.0.72", "status": "affected", "version": "5.6.0", "versionType": "custom" }, { "lessThan": "5.7.0.122", "status": "affected", "version": "5.7.0", "versionType": "custom" }, { "lessThan": "5.9.0.165", "status": "affected", "version": "5.9.0", "versionType": "custom" }, { "lessThan": "5.10.0.312", "status": "affected", "version": "5.10.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Open Banking KM", "vendor": "WSO2", "versions": [ { "lessThan": "1.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.3.0.114", "status": "affected", "version": "1.3.0", "versionType": "custom" }, { "lessThan": "1.4.0.130", "status": "affected", "version": "1.4.0", "versionType": "custom" }, { "lessThan": "1.5.0.120", "status": "affected", "version": "1.5.0", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A privilege escalation vulnerability exists in multiple [Vendor Name] products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions \u003cb\u003eonly when all of the following conditions are met\u003c/b\u003e:\u003cbr\u003e\u003cul\u003e\u003cli\u003eSOAP admin services are accessible to the attacker.\u003c/li\u003e\u003cli\u003eThe deployment includes an internally used attribute that is not part of the default WSO2 product configuration.\u003c/li\u003e\u003cli\u003eAt least one custom role exists with non-default permissions.\u003c/li\u003e\u003cli\u003eThe attacker has knowledge of the custom role and the internal attribute used in the deployment.\u003c/li\u003e\u003c/ul\u003eExploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.\u003cbr\u003e" } ], "value": "A privilege escalation vulnerability exists in multiple [Vendor Name] products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met:\n * SOAP admin services are accessible to the attacker.\n * The deployment includes an internally used attribute that is not part of the default WSO2 product configuration.\n * At least one custom role exists with non-default permissions.\n * The attacker has knowledge of the custom role and the internal attribute used in the deployment.\n\n\nExploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 4.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-863", "description": "CWE-863 Incorrect Authorization", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-05-30T15:00:56.617Z", "orgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "shortName": "WSO2" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3573/" } ], "solutions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Follow the instructions given on \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3573/#solution\"\u003ehttps://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3...\u003c/a\u003e \u003cbr\u003e" } ], "value": "Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3573/#solution" } ], "source": { "advisory": "WSO2-2024-3573", "discovery": "INTERNAL" }, "title": "Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "assignerShortName": "WSO2", "cveId": "CVE-2024-7096", "datePublished": "2025-05-30T14:54:32.417Z", "dateReserved": "2024-07-25T06:35:14.323Z", "dateUpdated": "2025-05-30T15:01:40.977Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-7097
Vulnerability from cvelistv5
Published
2025-05-30 15:04
Modified
2025-05-30 16:12
Severity ?
EPSS score ?
Summary
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
References
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-7097", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-05-30T16:05:35.324157Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-863", "description": "CWE-863 Incorrect Authorization", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-05-30T16:12:44.804Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "WSO2 Open Banking AM", "vendor": "WSO2", "versions": [ { "lessThan": "1.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.3.0.131", "status": "affected", "version": "1.3.0", "versionType": "custom" }, { "lessThan": "1.4.0.134", "status": "affected", "version": "1.4.0", "versionType": "custom" }, { "lessThan": "1.5.0.136", "status": "affected", "version": "1.5.0", "versionType": "custom" }, { "lessThan": "2.0.0.343", "status": "affected", "version": "2.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Open Banking KM", "vendor": "WSO2", "versions": [ { "lessThan": "1.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "1.3.0.114", "status": "affected", "version": "1.3.0", "versionType": "custom" }, { "lessThan": "1.4.0.130", "status": "affected", "version": "1.4.0", "versionType": "custom" }, { "lessThan": "1.5.0.120", "status": "affected", "version": "1.5.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Identity Server as Key Manager", "vendor": "WSO2", "versions": [ { "lessThan": "5.3.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "5.3.0.38", "status": "affected", "version": "5.3.0", "versionType": "custom" }, { "lessThan": "5.5.0.51", "status": "affected", "version": "5.5.0", "versionType": "custom" }, { "lessThan": "5.6.0.72", "status": "affected", "version": "5.6.0", "versionType": "custom" }, { "lessThan": "5.7.0.122", "status": "affected", "version": "5.7.0", "versionType": "custom" }, { "lessThan": "5.9.0.165", "status": "affected", "version": "5.9.0", "versionType": "custom" }, { "lessThan": "5.10.0.312", "status": "affected", "version": "5.10.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 API Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "2.0.0.29", "status": "affected", "version": "2.0.0", "versionType": "custom" }, { "lessThan": "2.1.0.39", "status": "affected", "version": "2.1.0", "versionType": "custom" }, { "lessThan": "2.2.0.56", "status": "affected", "version": "2.2.0", "versionType": "custom" }, { "lessThan": "2.5.0.83", "status": "affected", "version": "2.5.0", "versionType": "custom" }, { "lessThan": "2.6.0.142", "status": "affected", "version": "2.6.0", "versionType": "custom" }, { "lessThan": "3.0.0.162", "status": "affected", "version": "3.0.0", "versionType": "custom" }, { "lessThan": "3.1.0.294", "status": "affected", "version": "3.1.0", "versionType": "custom" }, { "lessThan": "3.2.0.384", "status": "affected", "version": "3.2.0", "versionType": "custom" }, { "lessThan": "3.2.1.16", "status": "affected", "version": "3.2.1", "versionType": "custom" }, { "lessThan": "4.0.0.305", "status": "affected", "version": "4.0.0", "versionType": "custom" }, { "lessThan": "4.1.0.166", "status": "affected", "version": "4.1.0", "versionType": "custom" }, { "lessThan": "4.2.0.101", "status": "affected", "version": "4.2.0", "versionType": "custom" }, { "lessThan": "4.3.0.16", "status": "affected", "version": "4.3.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Identity Server", "vendor": "WSO2", "versions": [ { "lessThan": "5.2.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "5.2.0.32", "status": "affected", "version": "5.2.0", "versionType": "custom" }, { "lessThan": "5.3.0.33", "status": "affected", "version": "5.3.0", "versionType": "custom" }, { "lessThan": "5.4.0.32", "status": "affected", "version": "5.4.0", "versionType": "custom" }, { "lessThan": "5.4.1.36", "status": "affected", "version": "5.4.1", "versionType": "custom" }, { "lessThan": "5.5.0.50", "status": "affected", "version": "5.5.0", "versionType": "custom" }, { "lessThan": "5.6.0.58", "status": "affected", "version": "5.6.0", "versionType": "custom" }, { "lessThan": "5.7.0.123", "status": "affected", "version": "5.7.0", "versionType": "custom" }, { "lessThan": "5.8.0.106", "status": "affected", "version": "5.8.0", "versionType": "custom" }, { "lessThan": "5.9.0.157", "status": "affected", "version": "5.9.0", "versionType": "custom" }, { "lessThan": "5.10.0.318", "status": "affected", "version": "5.10.0", "versionType": "custom" }, { "lessThan": "5.11.0.365", "status": "affected", "version": "5.11.0", "versionType": "custom" }, { "lessThan": "6.0.0.209", "status": "affected", "version": "6.0.0", "versionType": "custom" }, { "lessThan": "6.1.0.188", "status": "affected", "version": "6.1.0", "versionType": "custom" }, { "lessThan": "7.0.0.60", "status": "affected", "version": "7.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "product": "WSO2 Open Banking IAM", "vendor": "WSO2", "versions": [ { "lessThan": "2.0.0", "status": "unknown", "version": "0", "versionType": "custom" }, { "lessThan": "2.0.0.364", "status": "affected", "version": "2.0.0", "versionType": "custom" } ] }, { "defaultStatus": "unknown", "product": "WSO2 Enterprise Mobility Manager", "vendor": "WSO2", "versions": [ { "lessThan": "2.2.0.26", "status": "affected", "version": "2.2.0", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization.\u003cbr\u003e\u003cbr\u003eExploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.\u003cbr\u003e" } ], "value": "An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization.\n\nExploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "providerMetadata": { "dateUpdated": "2025-05-30T15:04:09.940Z", "orgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "shortName": "WSO2" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3574/" } ], "solutions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: transparent;\"\u003eFollow the instructions given on\u0026nbsp;\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3574/#solution\"\u003ehttps://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3...\u003c/a\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "Follow the instructions given on\u00a0 https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3574/#solution" } ], "source": { "advisory": "WSO2-2024-3574", "discovery": "INTERNAL" }, "title": "Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8", "assignerShortName": "WSO2", "cveId": "CVE-2024-7097", "datePublished": "2025-05-30T15:04:09.940Z", "dateReserved": "2024-07-25T07:26:31.718Z", "dateUpdated": "2025-05-30T16:12:44.804Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }