ZDI-24-1741: WSO2 API Manager SynapseArtifactUploaderAdmin Unrestricted File Upload Remote Code Execution Vulnerability
Published Dec 30, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WSO2 API Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-7074.
Affected Software
1 affected component
WSO2 API Manager
Event History
Dec 30, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1741?
The severity of ZDI-24-1741 is rated at 7.2 according to the CVSS score.
2
What type of vulnerability is ZDI-24-1741?
ZDI-24-1741 is a remote code execution vulnerability that requires authentication to exploit.
3
Which software is affected by ZDI-24-1741?
ZDI-24-1741 affects installations of WSO2 API Manager.
4
How do I fix ZDI-24-1741?
To fix ZDI-24-1741, you should apply the latest security updates provided by WSO2 for the API Manager.
5
What is the impact of exploiting ZDI-24-1741?
Exploiting ZDI-24-1741 allows remote attackers to execute arbitrary code on the affected WSO2 API Manager installations.