An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.
Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.
References
| Link | Resource |
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ | Vendor Advisory |
Configurations
History
06 Oct 2025, 13:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wso2
Wso2 identity Server |
|
| References | () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ - Vendor Advisory | |
| CPE | cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:* |
23 May 2025, 15:54
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
22 May 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-22 19:15
Updated : 2025-10-06 13:57
NVD link : CVE-2024-7487
Mitre link : CVE-2024-7487
CVE.ORG link : CVE-2024-7487
JSON object : View
Products Affected
wso2
- identity_server
CWE
CWE-287
Improper Authentication
