Lucene search

K
nessusThis script is Copyright (C) 2022-2024 and is owned by Tenable, Inc. or an Affiliate thereof.WSO2_CVE-2022-29464.NBIN
HistoryApr 26, 2022 - 12:00 a.m.

WSO2 Multiple Products File Upload Remote Command Execution (CVE-2022-29464)

2022-04-2600:00:00
This script is Copyright (C) 2022-2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
298

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.974 High

EPSS

Percentile

100.0%

The remote web server is running a WSO2 product that is affected by a file upload remote command execution vulnerability due to improper validation of user input. A remote, unauthenticated attacker can leverage this by uploading a malicious jsp script to the web server resulting in remote command execution.

Note that Nessus tests for this vulnerability by sending a benign POST request to the vulnerable endpoint and analyzes the response to determine if the vulnerability is present or has been patched or mitigated.

Binary data wso2_CVE-2022-29464.nbin
VendorProductVersionCPE
wso2identity_server_analyticscpe:/a:wso2:identity_server_analytics
wso2api_managercpe:/a:wso2:api_manager
wso2identity_server_as_key_managercpe:/a:wso2:identity_server_as_key_manager
wso2identity_servercpe:/a:wso2:identity_server
wso2enterprise_integratorcpe:/a:wso2:enterprise_integrator

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.974 High

EPSS

Percentile

100.0%