CVE Database
/

CVE-2024-6914

Back to search

CVE-2024-6914

Published: May 22, 2025

Modified: Aug 27, 2025

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated privileges. This vulnerability is exploitable only through the account recovery SOAP admin services exposed via the "/services" context path in affected products. The impact may be reduced if access to these endpoints has been restricted based on the "Security Guidelines for Production Deployment" by disabling exposure to untrusted networks.

VendorProductVersions

WSO2

WSO2 API Manager

unknown
0 - < 2.2.0
affected
2.2.0 - < 2.2.0.55
affected
2.5.0 - < 2.5.0.82
affected
2.6.0 - < 2.6.0.141
affected
3.0.0 - < 3.0.0.161

+7 more versions

WSO2

WSO2 Governance Registry

affected
5.4.0 - < 5.4.0.14

WSO2

WSO2 Identity Server

unknown
0 - < 5.3.0
affected
5.3.0 - < 5.3.0.31
affected
5.4.0 - < 5.4.0.30
affected
5.4.1 - < 5.4.1.35
affected
5.5.0 - < 5.5.0.48

+9 more versions

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.3.0
affected
5.3.0 - < 5.3.0.36
affected
5.5.0 - < 5.5.0.49
affected
5.6.0 - < 5.6.0.70
affected
5.7.0 - < 5.7.0.121

+2 more versions

WSO2

WSO2 IoT

affected
3.3.0 - < 3.3.0.59
affected
3.3.1 - < 3.3.1.61

WSO2

WSO2 Open Banking AM

unknown
0 - < 1.3.0
affected
1.3.0 - < 1.3.0.130
affected
1.4.0 - < 1.4.0.133
affected
1.5.0 - < 1.5.0.135
affected
2.0.0 - < 2.0.0.341

WSO2

WSO2 Open banking KM

unknown
0 - < 1.3.0
affected
1.3.0 - < 1.3.0.113
affected
1.4.0 - < 1.4.0.129
affected
1.5.0 - < 1.5.0.119

WSO2

WSO2 Open Banking IAM

affected
2.0.0 - < 2.0.0.362

WSO2

WSO2 Carbon Identity Management

affected
5.7.5 - < 5.7.5.9
affected
5.10.86 - < 5.10.86.4
affected
5.10.112 - < 5.10.112.14
affected
5.11.148 - < 5.11.148.13
affected
5.11.256 - < 5.11.256.15

+13 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now