ZDI-CAN-23650: ZDI-24-1740: WSO2 API Manager Exposed Dangerous Function Authentication Bypass Vulnerability
Published Dec 30, 2024
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of WSO2 API Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2024-6914.
Affected Software
1 affected component
WSO2 API Manager
Event History
Dec 30, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23650?
The severity of ZDI-CAN-23650 is rated at 8.1 on the CVSS scale.
2
How do I fix ZDI-CAN-23650?
To fix ZDI-CAN-23650, update to the latest version of WSO2 API Manager or apply any available security patches.
3
What type of vulnerability is ZDI-CAN-23650?
ZDI-CAN-23650 is an authentication bypass vulnerability that permits remote attackers to exploit affected installations.
4
Which versions of WSO2 API Manager are affected by ZDI-CAN-23650?
All versions of WSO2 API Manager that are not patched against this vulnerability are affected by ZDI-CAN-23650.
5
Is authentication required to exploit ZDI-CAN-23650?
No, authentication is not required to exploit ZDI-CAN-23650.