CVE-2024-6914: Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated privileges.
This vulnerability is exploitable only through the account recovery SOAP admin services exposed via the "/services" context path in affected products. The impact may be reduced if access to these endpoints has been restricted based on the "Security Guidelines for Production Deployment" by disabling exposure to untrusted networks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6914?
CVE-2024-6914 has a high severity rating due to its potential for complete account takeover.
How do I fix CVE-2024-6914?
To fix CVE-2024-6914, apply the latest security patches provided by WSO2 for affected products.
Which WSO2 products are affected by CVE-2024-6914?
CVE-2024-6914 affects multiple WSO2 products that utilize the vulnerable account recovery-related SOAP admin service.
Who can exploit CVE-2024-6914?
Any malicious actor can exploit CVE-2024-6914 to reset the password of any user account.
What is the potential impact of CVE-2024-6914?
The potential impact of CVE-2024-6914 includes unauthorized access and total takeover of user accounts.