First published: Mon Apr 18 2022(Updated: )
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 API Manager | >=2.2.0<=4.0.0 | |
WSO2 Enterprise Integrator | >=6.2.0<=6.6.0 | |
WSO2 Identity Server | >=5.2.0<=5.11.0 | |
WSO2 Identity Server Analytics | =5.4.0 | |
WSO2 Identity Server Analytics | =5.4.1 | |
WSO2 Identity Server Analytics | =5.5.0 | |
WSO2 Identity Server Analytics | =5.6.0 | |
WSO2 Identity Server as Key Manager | >=5.3.0<=5.10.0 | |
WSO2 Open Banking AM | >=1.3.0<=2.0.0 | |
Wso2 Open Banking Iam | =2.0.0 | |
WSO2 Open Banking KM | >=1.3.0<=1.5.0 | |
WSO2 Multiple Products | ||
>=2.2.0<=4.0.0 | ||
>=6.2.0<=6.6.0 | ||
>=5.2.0<=5.11.0 | ||
=5.4.0 | ||
=5.4.1 | ||
=5.5.0 | ||
=5.6.0 | ||
>=5.3.0<=5.10.0 | ||
>=1.3.0<=2.0.0 | ||
=2.0.0 | ||
>=1.3.0<=1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29464 is a vulnerability that allows unrestricted file upload with resultant remote code execution in certain WSO2 products.
CVE-2022-29464 has a severity rating of 9.8 (critical).
WSO2 API Manager, WSO2 Enterprise Integrator, WSO2 Identity Server, WSO2 Identity Server Analytics, and WSO2 Identity Server as Key Manager are affected by CVE-2022-29464.
An attacker can exploit CVE-2022-29464 by using a /fileupload endpoint with a Content-Disposition directory traversal sequence to upload malicious files and execute remote code.
You can find more information about CVE-2022-29464 on the following sources: [Packet Storm Security](http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-Code-Execution.html), [Openwall OSS Security Mailing List](http://www.openwall.com/lists/oss-security/2022/04/22/7), [WSO2 Security Advisory](https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738).