PT-2022-2322 · Wso2 · Wso2 Identity Server As Key Manager+5
Orange Tsai
·
Published
2022-04-01
·
Updated
2025-12-27
·
CVE-2022-29464
CVSS v3.1
10
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
WSO2 API Manager versions 2.2.0 through 4.0.0
WSO2 Identity Server versions 5.2.0 through 5.11.0
WSO2 Identity Server Analytics versions 5.4.0, 5.4.1, 5.5.0, and 5.6.0
WSO2 Identity Server as Key Manager versions 5.3.0 through 5.11.0
WSO2 Enterprise Integrator versions 6.2.0 through 6.6.0
WSO2 Open Banking AM versions 1.4.0 through 2.0.0
WSO2 Open Banking KM versions 1.4.0 through 2.0.0
Description
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a "/fileupload" endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This vulnerability can be exploited by uploading malicious JSP files to the server, allowing unauthorized remote code execution.
Recommendations
For WSO2 API Manager versions 2.2.0 through 4.0.0, update to a version that contains a fix for this vulnerability.
For WSO2 Identity Server versions 5.2.0 through 5.11.0, update to a version that contains a fix for this vulnerability.
For WSO2 Identity Server Analytics versions 5.4.0, 5.4.1, 5.5.0, and 5.6.0, update to a version that contains a fix for this vulnerability.
For WSO2 Identity Server as Key Manager versions 5.3.0 through 5.11.0, update to a version that contains a fix for this vulnerability.
For WSO2 Enterprise Integrator versions 6.2.0 through 6.6.0, update to a version that contains a fix for this vulnerability.
For WSO2 Open Banking AM versions 1.4.0 through 2.0.0, update to a version that contains a fix for this vulnerability.
For WSO2 Open Banking KM versions 1.4.0 through 2.0.0, update to a version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the "/fileupload" endpoint until a patch is available.
Exploit
Fix
RCE
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wso2 Api Manager
Wso2 Enterprise Integrator
Wso2 Identity Server
Wso2 Identity Server Analytics
Wso2 Identity Server As Key Manager
Wso2 Open Banking Am