PT-2025-23313 · Wso2+2 · Wso2 Api Manager+13
Published
2025-05-30
·
Updated
2025-12-03
·
CVE-2024-7096
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined.
Description
A privilege escalation issue exists due to a business logic flaw in SOAP admin services. This can be exploited when specific conditions are met, including accessibility of SOAP admin services to the attacker, the presence of an internally used attribute not part of the default configuration, the existence of at least one custom role with non-default permissions, and the attacker's knowledge of the custom role and internal attribute. Exploiting this issue allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Api Manager
Wso2 Enterprise Mobility Manager
Wso2 Identity Server
Wso2 Identity Server As Key Manager
Wso2 Open Banking Am
Aimanager
Identityserver
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Org.Wso2.Am:Am-Parent
Org.Wso2.Is:Identity-Server-Parent
Product-Apim