Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
http://www.openwall.com/lists/oss-security/2022/04/22/7 | Mailing List Third Party Advisory |
https://github.com/hakivvi/CVE-2022-29464 | Exploit Third Party Advisory |
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Jul 2024, 17:05
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wso2 open Banking Am
Wso2 open Banking Km Wso2 open Banking Iam |
|
CPE | cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:* |
|
References | () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ - Vendor Advisory |
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 |
09 Sep 2022, 16:54
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry |
02 May 2022, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Apr 2022, 18:47
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server_analytics:5.6.0:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server_analytics:5.5.0:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server_analytics:5.4.1:*:*:*:*:*:*:* cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server_analytics:5.4.0:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:* |
|
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
References | (MISC) https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738 - Mitigation, Vendor Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2022/04/22/7 - Mailing List, Third Party Advisory | |
References | (MISC) https://github.com/hakivvi/CVE-2022-29464 - Exploit, Third Party Advisory |
23 Apr 2022, 04:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0. | |
References |
|
22 Apr 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Apr 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-04-18 22:15
Updated : 2024-07-02 17:05
NVD link : CVE-2022-29464
Mitre link : CVE-2022-29464
CVE.ORG link : CVE-2022-29464
JSON object : View
Products Affected
wso2
- identity_server_as_key_manager
- open_banking_iam
- open_banking_am
- identity_server
- open_banking_km
- identity_server_analytics
- enterprise_integrator
- api_manager
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')