logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-29464

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-29464

Description:
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Last updated date:
10/23/2023

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
04/25/2022
Reference url to background

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/20/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/22/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/22/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/24/2022
Reference url to background

https://github.com/oppsec/WSOB

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/25/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/28/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/30/2022
Reference url to background

https://github.com/UUFR/CVE-2022-29464

Type:
exploit
Confidence:
HIGH
Date of publishing:
05/02/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/15/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/26/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/22/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/05/2022
Reference url to background

https://github.com/Pasch0/WSO2RCE

Type:
exploit
Confidence:
HIGH
Date of publishing:
08/01/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/01/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
09/09/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/14/2022
Reference url to background

https://github.com/gbrsh/CVE-2022-29464

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/25/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/25/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2023

Privacy Policy