CVE-2022-29464
Description
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
StableCommon Consequences
Applicable Platforms
Enterprise Integrator by Wso2
cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*
Open Banking Am by Wso2
cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*
Identity Server Analytics by Wso2
cpe:2.3:a:wso2:identity_server_analytics:5.5.0:*:*:*:*:*:*:*
Identity Server Analytics by Wso2
cpe:2.3:a:wso2:identity_server_analytics:5.6.0:*:*:*:*:*:*:*
Identity Server As Key Manager by Wso2
cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*
Open Banking Km by Wso2
cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*
Identity Server Analytics by Wso2
cpe:2.3:a:wso2:identity_server_analytics:5.4.1:*:*:*:*:*:*:*
Api Manager by Wso2
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Identity Server Analytics by Wso2
cpe:2.3:a:wso2:identity_server_analytics:5.4.0:*:*:*:*:*:*:*
Open Banking Iam by Wso2
cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*
Identity Server by Wso2
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*