« Volver al listado

CVE-2024-7487

Estado: AnalizadaMedia (5.8)—

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.

Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7487",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7487",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-22T19:23:42.783012Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "vendor": "WSO2",
          "product": "WSO2 Identity Server",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.0",
              "lessThan": "7.0.0.65",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "Client Attestation Filter",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.26",
              "lessThan": "7.0.26.24",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.0.51",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.inbound.auth.oauth2:org.wso2.carbon.identity.client.attestation.filter",
          "defaultStatus": "unknown"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon Identity Client Attestation Met Data Mgt BE",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.78",
              "lessThan": "7.0.78.44",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.1.30",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.framework:org.wso2.carbon.identity.client.attestation.mgt",
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-05-22T19:15:43.157",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.\n\nExploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de autenticación incorrecta en WSO2 Identity Server 7.0.0 debido a un fallo de implementación que permite omitir la autenticación nativa de la aplicación al pasar un objeto no válido. La explotación de esta vulnerabilidad podría permitir a actores maliciosos eludir el mecanismo de verificación del cliente, comprometiendo así la integridad del proceso de autenticación."
    }
  ],
  "lastModified": "2026-06-17T08:20:17.950",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1EFBD0F-9664-4EF3-9908-C72B1318F68F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}