Wso2
Wso2 Open Banking KM: vulnerabilidades y CVE
Wso2 Open Banking KM tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-29464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 abr 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-15039 | Crítica (9.4) | 0.67% | — | 6 ago 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is… |
| CVE-2025-9312 | Crítica (9.8) | 0.24% | — | 18 nov 2025 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client… |
| CVE-2025-10611 | Crítica (9.8) | 0.82% | — | 16 oct 2025 | Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation.… |
| CVE-2025-9804 | Media (6.5) | 0.56% | — | 16 oct 2025 | An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this… |
| CVE-2024-7073 | Media (6.5) | 0.22% | — | 2 jun 2025 | A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests,… |
| CVE-2024-7097 | Media (4.3) | 0.66% | — | 30 may 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This… |
| CVE-2024-7096 | Media (5.4) | 0.71% | — | 30 may 2025 | Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms. |
| CVE-2024-6914 | Crítica (9.8) | 0.72% | — | 22 may 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the… |
| CVE-2022-29464 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 abr 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.