CVE Database
/

CVE-2024-7073

Back to search

CVE-2024-7073

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.

VendorProductVersions

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.3.0
affected
5.3.0 - < 5.3.0.37
affected
5.5.0 - < 5.5.0.50
affected
5.6.0 - < 5.6.0.71
affected
5.7.0 - < 5.7.0.122

+2 more versions

WSO2

WSO2 Identity Server

unknown
0 - < 5.2.0
affected
5.2.0 - < 5.2.0.32
affected
5.3.0 - < 5.3.0.32
affected
5.4.0 - < 5.4.0.31
affected
5.4.1 - < 5.4.1.36

+10 more versions

WSO2

WSO2 Open Banking KM

unknown
0 - < 1.3.0
affected
1.3.0 - < 1.3.0.114
affected
1.4.0 - < 1.4.0.130
affected
1.5.0 - < 1.5.0.120

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.363

WSO2

WSO2 Carbon Policy Editor BE

affected
5.2.2 - < 5.2.2.14
affected
5.7.5 - < 5.7.5.15
affected
5.10.86 - < 5.10.86.5
affected
5.10.112 - < 5.10.112.16
affected
5.11.148 - < 5.11.148.15

+10 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now