CVE-2024-7073

MEDIUM EPSS 8.5%
Published Jun 2, 20251y ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Medium
Find Similar
Published Jun 2, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.

CVSS Details

Base Score
6.5
Exploitability
2.8
Impact
3.6
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Adjacent
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
8.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-918 Server-Side Request Forgery (SSRF) Validation

Affected Products 24

VendorProductVersionRange
wso2identity_server5.2.0any
wso2identity_server5.3.0any
wso2identity_server5.4.0any
wso2identity_server5.4.1any
wso2identity_server5.5.0any
wso2identity_server5.6.0any
wso2identity_server5.7.0any
wso2identity_server5.8.0any
wso2identity_server5.9.0any
wso2identity_server5.10.0any
wso2identity_server5.11.0any
wso2identity_server6.0.0any
wso2identity_server6.1.0any
wso2identity_server7.0.0any
wso2identity_server_as_key_manager5.3.0any
wso2identity_server_as_key_manager5.5.0any
wso2identity_server_as_key_manager5.6.0any
wso2identity_server_as_key_manager5.7.0any
wso2identity_server_as_key_manager5.9.0any
wso2identity_server_as_key_manager5.10.0any
wso2open_banking_iam2.0.0any
wso2open_banking_km1.3.0any
wso2open_banking_km1.4.0any
wso2open_banking_km1.5.0any

References 1

  • security.docs.wso2.com https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3562
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.