peter bassill · operator
$ cve CVE-2022-29464 JSON

CVE-2022-29464 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-16.

Description

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-05-16
Public exploitnone known
Published2022-04-18
Last modified2026-06-17

CISA KEV

NameWSO2 Multiple Products Unrestrictive Upload of File Vulnerability
Added2022-04-25
Due2022-05-16
Vendor / productWSO2 / Multiple Products
Ransomware useknown

Affected (8)

VendorProduct
wso2api manager
wso2enterprise integrator
wso2identity server
wso2identity server analytics
wso2identity server as key manager
wso2open banking am
wso2open banking iam
wso2open banking km

References

→ the Explorer  ·  watch your stack  ·  NVD