CVE-2022-29464

    Dashboard / Vulnerabilities / CVE-2022-29464

    CVE-2022-29464

    Published: 18 Apr 2022Last Modified: 12 Aug 2026

    Summary:

    Details: Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 5cdc3f8a5ea212c3bf231cb710ea3436e9aad1d7
    Fixed -None

    Affected versions

    v4.0.0-rc
    v4.0.0
    v4.0.0-beta
    v4.0.0-alpha
    v4.0.0-m8
    v4.0.0-m7
    v4.0.0-m6
    v4.0.0-m5
    v4.0.0-m4
    v4.0.0-m3
    v4.0.0-m2
    v4.0.0-m1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-29464 | CVE-DB