CVE-2022-29464
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22
מוצרים מושפעים
wso2: api manager; wso2: enterprise integrator; wso2: identity server; wso2: identity server analytics; wso2: identity server as key manager; wso2: open banking am; wso2: open banking iam; wso2: open banking km
קישורים
- https://security.docs.wso2.com/en/latest/security-announcements/security-advis… Vendor Advisory
- https://security.docs.wso2.com/en/latest/security-announcements/security-advis… Vendor Advisory
- http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-C… ExploitThird Party AdvisoryVDB Entry
- https://github.com/hakivvi/CVE-2022-29464 ExploitThird Party Advisory
- http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-C… ExploitThird Party AdvisoryVDB Entry
- https://github.com/hakivvi/CVE-2022-29464 ExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/04/22/7 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/04/22/7 Mailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource