← All CVEs

CVE-2022-29464

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-25Remediation due 2022-05-16

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

9.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2022-04-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
wso2api_manager>= 2.2.0, <= 4.0.0
wso2enterprise_integrator>= 6.2.0, <= 6.6.0
wso2identity_server>= 5.2.0, <= 5.11.0
wso2identity_server_analytics5.4.0
wso2identity_server_analytics5.4.1
wso2identity_server_analytics5.5.0
wso2identity_server_analytics5.6.0
wso2identity_server_as_key_manager>= 5.3.0, <= 5.10.0
wso2open_banking_am>= 1.3.0, <= 2.0.0
wso2open_banking_iam2.0.0
wso2open_banking_km>= 1.3.0, <= 1.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-29464