CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 18, 2022
Published Date
April 18, 2022
Last Updated
January 29, 2025
Vendor
n/a
Product
n/a
Description
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-04-25 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2022-04-21 14:47:18 UTC) Source
Used in Malware
Yes (added 2022-04-25 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-04-25 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

wso2_file_upload_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2022-29464

ThatNotEasy/CVE-2022-29464

Type: github • Created: 2023-04-25 09:45:18 UTC • Stars: 6

Perform With Mass Exploits In WSO Management.

gbrsh/CVE-2022-29464

Type: github • Created: 2022-11-14 18:22:41 UTC • Stars: 7

RCE exploit for WSO2

hupe1980/CVE-2022-29464

Type: github • Created: 2022-09-22 14:04:49 UTC • Stars: 3

WSO2 Arbitrary File Upload to Remote Command Execution (RCE)

amit-pathak009/CVE-2022-29464-mass

Type: github • Created: 2022-08-13 18:15:18 UTC • Stars: 1

r4x0r1337/-CVE-2022-29464

Type: github • Created: 2022-08-01 07:27:29 UTC • Stars: 4

g0dxing/CVE-2022-29464

Type: github • Created: 2022-06-28 01:10:41 UTC • Stars: 0

Python script to exploit CVE-2022-29464 (mass mode)

jimidk/Better-CVE-2022-29464

Type: github • Created: 2022-06-04 16:46:52 UTC • Stars: 4

CVE-2022-29464 PoC for WSO2 products

Chocapikk/CVE-2022-29464

Type: github • Created: 2022-05-26 20:19:53 UTC • Stars: 3

Python script to exploit CVE-2022-29464 (mass mode)

Inplex-sys/CVE-2022-29464-loader

Type: github • Created: 2022-05-15 08:51:16 UTC • Stars: 10

A bots loader for CVE-2022-29464 with multithreading

superzerosec/CVE-2022-29464

Type: github • Created: 2022-04-29 08:24:17 UTC • Stars: 2

CVE-2022-29464 POC exploit

gpiechnik2/nmap-CVE-2022-29464

Type: github • Created: 2022-04-22 21:23:57 UTC • Stars: 3

Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.

hev0x/CVE-2022-29464

Type: github • Created: 2022-04-22 05:19:51 UTC • Stars: 3

WSO2 RCE (CVE-2022-29464)

mr-r3bot/WSO2-CVE-2022-29464

Type: github • Created: 2022-04-21 14:47:18 UTC • Stars: 2

Pre-auth RCE bug CVE-2022-29464

hakivvi/CVE-2022-29464

Type: github • Created: 2022-04-20 21:23:52 UTC • Stars: 372

WSO2 RCE (CVE-2022-29464) exploit and writeup.