CVE Database
/

CVE-2024-7074

Back to search

CVE-2024-7074

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

CVSS v3.1

6.8

MEDIUM

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server. By leveraging this vulnerability, an attacker could upload a specially crafted payload, potentially achieving remote code execution (RCE) on the server. Exploitation requires valid admin credentials, limiting its impact to authorized but potentially malicious users.

VendorProductVersions

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.0.0
affected
6.0.0 - < 6.0.0.21
affected
6.1.0 - < 6.1.0.38
affected
6.1.1 - < 6.1.1.42
affected
6.2.0 - < 6.2.0.61

+4 more versions

WSO2

WSO2 API Manager

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.28
affected
2.1.0 - < 2.1.0.38
affected
2.2.0 - < 2.2.0.57
affected
2.5.0 - < 2.5.0.83

+9 more versions

WSO2

WSO2 Enterprise Service Bus

affected
4.9.0 - < 4.9.0.10
affected
5.0.0 - < 5.0.0.28

WSO2

WSO2 Enterprise Mobility Manager

affected
2.2.0 - < 2.2.0.27

WSO2

WSO2 Micro Integrator

unknown
0 - < 1.0.0
affected
1.0.0 - < 1.0.0.49

WSO2

WSO2 Open Banking AM

unknown
0 - < 1.3.0
affected
1.3.0 - < 1.3.0.132
affected
1.4.0 - < 1.4.0.135
affected
1.5.0 - < 1.5.0.137
affected
2.0.0 - < 2.0.0.342

WSO2

WSO2 Carbon Synapse Artifact Uploader BE

affected
4.4.10 - < 4.4.10.3
affected
4.6.1 - < 4.6.1.4
affected
4.6.6 - < 4.6.6.9
affected
4.6.10 - < 4.6.10.4
affected
4.6.16 - < 4.6.16.2

+16 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now