WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
Summary
| CVE | CVE-2022-29464 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-18 22:15:00 UTC |
| Updated | 2023-10-23 22:15:00 UTC |
| Description | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0. |
Risk And Classification
EPSS: 0.944340000 probability, percentile 0.999860000 (date 2026-05-11)
CISA KEV: Listed on 2022-04-25; due 2022-05-16; ransomware use Known
Problem Types: CWE-22
CISA Known Exploited Vulnerability
| Vendor | WSO2 |
|---|---|
| Product | Multiple Products |
| Name | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2022-29464 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Api Manager | All | All | All | All |
| Application | Wso2 | Enterprise Integrator | All | All | All | All |
| Application | Wso2 | Identity Server | All | All | All | All |
| Application | Wso2 | Identity Server Analytics | 5.4.0 | All | All | All |
| Application | Wso2 | Identity Server Analytics | 5.4.1 | All | All | All |
| Application | Wso2 | Identity Server Analytics | 5.5.0 | All | All | All |
| Application | Wso2 | Identity Server Analytics | 5.6.0 | All | All | All |
| Application | Wso2 | Identity Server As Key Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE-2022-29464 :: WSO2 Unrestricted arbitrary file upload, and remote code to execution vulnerability. | MLIST | www.openwall.com | |
| GitHub - hakivvi/CVE-2022-29464: WSO2 RCE (CVE-2022-29464) exploit and writeup. | MISC | github.com | |
| Security Advisory WSO2-2021-1738 - WSO2 Platform Security - WSO2 Documentation | MISC | docs.wso2.com | |
| Just a moment... | MISC | security.docs.wso2.com | |
| WSO Arbitrary File Upload / Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150524 WSO2 File Upload Remote Command Execution Vulnerability (CVE-2022-29464)
- 150581 WSO2 File Upload Remote Command Execution Vulnerability (CVE-2022-29464)
- 730453 WSO2 Remote Code Execution (RCE) Vulnerability (CVE-2022-29464)
- 730454 WSO2 API Manager Unrestricted Arbitrary File Upload and Remote Code Execution (RCE) Vulnerability (WSO2-2021-1738)
- 730457 WSO2 Unrestricted Arbitrary File Upload and Remote Code Execution (RCE) Vulnerability (WSO2-2021-1738) (Intrusive Check)