KEVIntel
9.8
CVSS
Critical

CVE-2022-29464

PUBLISHED

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
WSO2
Product
WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM
Published
Apr 18, 2022
EPSS

Description

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N

Exploitation status

Exploited in the wild

Recorded 2022-04-25 00:00:00 UTC · Source

Used in malware

Recorded 2022-04-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 25, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

wso2_file_upload_rce

metasploit · Created Unknown

Metasploit module for CVE-2022-29464

Pushkarup/CVE-2022-29464

github · Created 2023-10-24 18:54:09 UTC · 1 stars

A PoC and Exploit for CVE 2022-29464

ThatNotEasy/CVE-2022-29464

github · Created 2023-04-25 09:45:18 UTC · 6 stars

Perform With Mass Exploits In WSO Management.

gbrsh/CVE-2022-29464

github · Created 2022-11-14 18:22:41 UTC · 7 stars

RCE exploit for WSO2

hupe1980/CVE-2022-29464

github · Created 2022-09-22 14:04:49 UTC · 3 stars

WSO2 Arbitrary File Upload to Remote Command Execution (RCE)

amit-pathak009/CVE-2022-29464-mass

github · Created 2022-08-13 18:15:18 UTC · 1 stars

r4x0r1337/-CVE-2022-29464

github · Created 2022-08-01 07:27:29 UTC · 4 stars

g0dxing/CVE-2022-29464

github · Created 2022-06-28 01:10:41 UTC · 0 stars

Python script to exploit CVE-2022-29464 (mass mode)

jimidk/Better-CVE-2022-29464

github · Created 2022-06-04 16:46:52 UTC · 4 stars

CVE-2022-29464 PoC for WSO2 products

Chocapikk/CVE-2022-29464

github · Created 2022-05-26 20:19:53 UTC · 3 stars

Python script to exploit CVE-2022-29464 (mass mode)

Inplex-sys/CVE-2022-29464-loader

github · Created 2022-05-15 08:51:16 UTC · 10 stars

A bots loader for CVE-2022-29464 with multithreading

superzerosec/CVE-2022-29464

github · Created 2022-04-29 08:24:17 UTC · 2 stars

CVE-2022-29464 POC exploit

gpiechnik2/nmap-CVE-2022-29464

github · Created 2022-04-22 21:23:57 UTC · 3 stars

Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.

hev0x/CVE-2022-29464

github · Created 2022-04-22 05:19:51 UTC · 3 stars

WSO2 RCE (CVE-2022-29464)

mr-r3bot/WSO2-CVE-2022-29464

github · Created 2022-04-21 14:47:18 UTC · 2 stars

Pre-auth RCE bug CVE-2022-29464

hakivvi/CVE-2022-29464

github · Created 2022-04-20 21:23:52 UTC · 372 stars

WSO2 RCE (CVE-2022-29464) exploit and writeup.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit