CVE-2022-29464
About
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Rainforest analyst review
Several WSO2 products share a flawed /fileupload endpoint that allows unrestricted file upload combined with directory traversal. An unauthenticated attacker sends a request whose Content-Disposition header carries a traversal sequence like ../../../../repository/deployment/server/webapps, dropping an attacker-controlled file, typically a JSP web shell, under the web root where the application server will execute it. The result is remote code execution with the privileges of the WSO2 process, reached with a single crafted upload and no login.
The affected span is wide, covering API Manager, Identity Server, Enterprise Integrator, and the Open Banking components across many versions, and these are identity and API-gateway systems that sit in the authentication path for other applications. That makes them a high-value pivot: a shell on an Identity Server is a foothold on the thing issuing tokens. Exploitation was observed in the wild soon after disclosure, with web shells and crypto-mining and Cobalt Strike payloads following. Apply the vendor's fixes for the specific product and version, and because the exploit window predates many patches, hunt for unexpected JSP files under the deployment webapps directories rather than assuming a clean patch closes the incident.
References
- http://packetstormsecurity.com/files/166921/WSO-Arbitrary-File-Upload-Remote-Code-Execution.html
- http://www.openwall.com/lists/oss-security/2022/04/22/7
- https://github.com/hakivvi/CVE-2022-29464
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29464
Related CVEs
Frequently asked questions
What is CVE-2022-29464?
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory.
How severe is CVE-2022-29464?
CVE-2022-29464 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-29464 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-29464?
Public advisories list the following as affected: api manager, enterprise integrator, identity server, identity server analytics, identity server as key manager, open banking am, +2. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-29464?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
