CVE-2024-7073
Last modified
CVE-2024-7073 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Identity Server | 5.2.0 |
| Wso2 | Identity Server | 5.3.0 |
| Wso2 | Identity Server | 5.4.0 |
| Wso2 | Identity Server | 5.4.1 |
| Wso2 | Identity Server | 5.5.0 |
| Wso2 | Identity Server | 5.6.0 |
| Wso2 | Identity Server | 5.7.0 |
| Wso2 | Identity Server | 5.8.0 |
| Wso2 | Identity Server | 5.9.0 |
| Wso2 | Identity Server | 5.10.0 |
| Wso2 | Identity Server | 5.11.0 |
| Wso2 | Identity Server | 6.0.0 |
| Wso2 | Identity Server | 6.1.0 |
| Wso2 | Identity Server | 7.0.0 |
| Wso2 | Identity Server As Key Manager | 5.3.0 |
| Wso2 | Identity Server As Key Manager | 5.5.0 |
| Wso2 | Identity Server As Key Manager | 5.6.0 |
| Wso2 | Identity Server As Key Manager | 5.7.0 |
| Wso2 | Identity Server As Key Manager | 5.9.0 |
| Wso2 | Identity Server As Key Manager | 5.10.0 |
| Wso2 | Open Banking Iam | 2.0.0 |
| Wso2 | Open Banking Km | 1.3.0 |
| Wso2 | Open Banking Km | 1.4.0 |
| Wso2 | Open Banking Km | 1.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-7073?
How severe is CVE-2024-7073?
How do I fix CVE-2024-7073?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-7065A vulnerability was found in Spina CMS up to 2.18.0. It has …4.3
- CVE-2024-7066A vulnerability was found in F-logic DataCube3 1.0. It has b…9.8
- CVE-2024-7067A vulnerability was found in kirilkirkov Ecommerce-Laravel-B…8.8
- CVE-2024-7068A vulnerability classified as problematic has been found in …4.6
- CVE-2024-7069A vulnerability, which was classified as critical, has been …7.5
- CVE-2024-7071Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2024-7074An arbitrary file upload vulnerability exists in multiple WS…6.8
- CVE-2024-7076Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2024-7077Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2024-7078Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2024-7079A flaw was found in the Openshift console. The /API/helm/ver…6.5
- CVE-2024-7080A vulnerability was found in SourceCodester Insurance Manage…7.5
Are you affected by CVE-2024-7073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
