CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_analytics:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_analytics:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_analytics:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_analytics:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*

History

02 Jul 2024, 17:05

Type Values Removed Values Added
CPE cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ - Vendor Advisory
First Time Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 open Banking Km

23 Oct 2023, 22:15

Type Values Removed Values Added
Summary Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0. Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

18 Oct 2023, 22:15

Type Values Removed Values Added
References
  • {'url': 'https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738', 'name': 'https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738', 'tags': ['Mitigation', 'Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ -

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-434 CWE-22

Information

Published : 2022-04-18 22:15

Updated : 2024-07-02 17:05


NVD link : CVE-2022-29464

Mitre link : CVE-2022-29464

CVE.ORG link : CVE-2022-29464


JSON object : View

Products Affected

wso2

  • api_manager
  • identity_server
  • open_banking_am
  • open_banking_iam
  • open_banking_km
  • identity_server_as_key_manager
  • enterprise_integrator
  • identity_server_analytics
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')