CVE-2022-29464
Description
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
In plain language
AI Act nowCVE-2022-29464 lets an attacker upload and run malicious code on exposed WSO2 servers without needing an account, so any small business running affected WSO2 products online should treat this as urgent to fix.
CVE-2022-29464 is an unauthenticated remote arbitrary file upload to a web-accessible location via the WSO2 /fileupload endpoint using a Content-Disposition directory traversal sequence, resulting in remote code execution; this has been added to CISA KEV for real-world ransomware use.
What to do now
- Check whether you run any of these WSO2 products: WSO2 API Manager, WSO2 Enterprise Integrator, WSO2 Identity Server (including Analytics and “as Key Manager”), or WSO2 Open Banking AM/KM, and note your exact version.
- If your version falls within the vulnerable ranges reported for CVE-2022-29464, confirm whether the /fileupload endpoint is reachable from the internet (publicly accessible) on that product.
- Upgrade/patch using the official WSO2 remediation in the advisory for WSO2-2021-1738 (use the fixed release versions listed there for your specific product and version).
- If you cannot patch immediately, restrict network access so the affected /fileupload endpoint is not reachable from the internet, and remove/disable any exposure path that allows direct calls to /fileupload.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-29464 and every CVE in our database. Create a free account — no credit card required.
Create Free Account