ZDI-24-1740: WSO2 API Manager Exposed Dangerous Function Authentication Bypass Vulnerability
Published Dec 30, 2024
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of WSO2 API Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2024-6914.
Affected Software
1 affected component
WSO2 API Manager
Event History
Dec 30, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1740?
The severity of ZDI-24-1740 is rated at 8.1 on the CVSS scale, indicating it's a high-severity vulnerability.
2
How do I fix ZDI-24-1740?
To fix ZDI-24-1740, ensure that your WSO2 API Manager is updated to the latest version that addresses this vulnerability.
3
What systems are affected by ZDI-24-1740?
ZDI-24-1740 affects installations of WSO2 API Manager where authentication can be bypassed.
4
Can ZDI-24-1740 be exploited remotely?
Yes, ZDI-24-1740 allows remote attackers to bypass authentication without the need for local access.
5
What is the associated CVE for ZDI-24-1740?
The associated CVE for ZDI-24-1740 is CVE-2024-6914.