PT-2025-23313 · Wso2+2 · Wso2 Api Manager+13

Published

2025-05-30

·

Updated

2025-12-03

·

CVE-2024-7096

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description A privilege escalation issue exists due to a business logic flaw in SOAP admin services. This can be exploited when specific conditions are met, including accessibility of SOAP admin services to the attacker, the presence of an internally used attribute not part of the default configuration, the existence of at least one custom role with non-default permissions, and the attacker's knowledge of the custom role and internal attribute. Exploiting this issue allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7096
GHSA-J63J-7R7R-5V4J

Affected Products

Wso2 Api Manager
Wso2 Enterprise Mobility Manager
Wso2 Identity Server
Wso2 Identity Server As Key Manager
Wso2 Open Banking Am
Aimanager
Identityserver
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Org.Wso2.Am:Am-Parent
Org.Wso2.Is:Identity-Server-Parent
Product-Apim