ZDI-CAN-26065: ZDI-24-1741: WSO2 API Manager SynapseArtifactUploaderAdmin Unrestricted File Upload Remote Code Execution Vulnerability
Published Dec 30, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WSO2 API Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-7074.
Affected Software
1 affected component
WSO2 API Manager
Event History
Dec 30, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-26065?
The vulnerability ZDI-CAN-26065 has been assigned a CVSS rating of 7.2, indicating its high severity.
2
How do I fix ZDI-CAN-26065?
To mitigate ZDI-CAN-26065, users should apply the latest security patches provided by WSO2 for the API Manager.
3
What are the potential impacts of exploiting ZDI-CAN-26065?
Exploiting ZDI-CAN-26065 can allow remote attackers to execute arbitrary code on affected installations of WSO2 API Manager.
4
Is authentication required to exploit ZDI-CAN-26065?
Yes, authentication is required to exploit the vulnerability ZDI-CAN-26065.
5
Which product versions are affected by ZDI-CAN-26065?
ZDI-CAN-26065 affects installations of WSO2 API Manager.