CVE Database
/

CVE-2024-7487

Back to search

CVE-2024-7487

Published: May 22, 2025

Modified: May 22, 2025

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

VendorProductVersions

WSO2

WSO2 Identity Server

affected
7.0.0 - < 7.0.0.65

WSO2

Client Attestation Filter

affected
7.0.26 - < 7.0.26.24
unaffected
7.0.51 - <= *

WSO2

WSO2 Carbon Identity Client Attestation Met Data Mgt BE

affected
7.0.78 - < 7.0.78.44
unaffected
7.1.30 - <= *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now