PT-2025-22560 · Wso2 · Wso2 Identity Server

Published

2025-05-22

·

Updated

2025-05-22

·

CVE-2024-7487

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Identity Server version 7.0.0
Description An improper authentication issue exists due to an implementation flaw, allowing app-native authentication to be bypassed when an invalid object is passed. This could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.
Recommendations For WSO2 Identity Server version 7.0.0, update to a version that fixes the improper authentication flaw to prevent the bypassing of app-native authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-7487

Affected Products

Wso2 Identity Server