CVE Tools

Description

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

In plain language

AI Act now

CVE-2022-29464 lets an attacker upload and run malicious code on exposed WSO2 servers without needing an account, so any small business running affected WSO2 products online should treat this as urgent to fix.

Executive summary

CVE-2022-29464 is an unauthenticated remote arbitrary file upload to a web-accessible location via the WSO2 /fileupload endpoint using a Content-Disposition directory traversal sequence, resulting in remote code execution; this has been added to CISA KEV for real-world ransomware use.

If affected, business impact
Full server takeoverRansomware and data theftService outage and downtimeMalicious web shell persistence

What to do now

  1. Check whether you run any of these WSO2 products: WSO2 API Manager, WSO2 Enterprise Integrator, WSO2 Identity Server (including Analytics and “as Key Manager”), or WSO2 Open Banking AM/KM, and note your exact version.
  2. If your version falls within the vulnerable ranges reported for CVE-2022-29464, confirm whether the /fileupload endpoint is reachable from the internet (publicly accessible) on that product.
  3. Upgrade/patch using the official WSO2 remediation in the advisory for WSO2-2021-1738 (use the fixed release versions listed there for your specific product and version).
  4. If you cannot patch immediately, restrict network access so the affected /fileupload endpoint is not reachable from the internet, and remove/disable any exposure path that allows direct calls to /fileupload.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Apr 25, 2022
Remediation due:May 16, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

and 8 more references View all →
2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2022-29464 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store