// For flags

CVE-2024-7073

Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin Services

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.

Existe una vulnerabilidad de server-side request forgery (SSRF) en varios productos WSO2 debido a una validación de entrada incorrecta en los servicios de administración SOAP. Esta falla permite a atacantes no autenticados manipular las solicitudes del lado del servidor, lo que permite el acceso a recursos internos y externos disponibles a través de la red o el sistema de archivos. La explotación de esta vulnerabilidad podría provocar el acceso no autorizado a datos y sistemas confidenciales, incluidos recursos dentro de redes privadas, siempre que sean accesibles para el producto afectado.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-07-24 CVE Reserved
  • 2025-06-02 CVE Published
  • 2025-06-02 CVE Updated
  • 2025-07-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.3.0.0 < 5.3.0.37
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.3.0.0 < 5.3.0.37"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.5.0.0 < 5.5.0.50
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.5.0.0 < 5.5.0.50"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.6.0.0 < 5.6.0.71
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.6.0.0 < 5.6.0.71"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.7.0.0 < 5.7.0.122
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.7.0.0 < 5.7.0.122"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.9.0.0 < 5.9.0.165
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.9.0.0 < 5.9.0.165"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server As Key Manager
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager"
>= 5.10.0.0 < 5.10.0.312
Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.10.0.0 < 5.10.0.312"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.2.0.0 < 5.2.0.32
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.2.0.0 < 5.2.0.32"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.3.0.0 < 5.3.0.32
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.3.0.0 < 5.3.0.32"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.4.0.0 < 5.4.0.31
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.4.0.0 < 5.4.0.31"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.4.1.0 < 5.4.1.36
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.4.1.0 < 5.4.1.36"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.5.0.0 < 5.5.0.49
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.5.0.0 < 5.5.0.49"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.6.0.0 < 5.6.0.57
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.6.0.0 < 5.6.0.57"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.7.0.0 < 5.7.0.123
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.7.0.0 < 5.7.0.123"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.8.0.0 < 5.8.0.105
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.8.0.0 < 5.8.0.105"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.9.0.0 < 5.9.0.156
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.9.0.0 < 5.9.0.156"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.10.0.0 < 5.10.0.318
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.10.0.0 < 5.10.0.318"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 5.11.0.0 < 5.11.0.364
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.11.0.0 < 5.11.0.364"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 6.0.0.0 < 6.0.0.208
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 6.0.0.0 < 6.0.0.208"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 6.1.0.0 < 6.1.0.187
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 6.1.0.0 < 6.1.0.187"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Identity Server
Search vendor "WSO2" for product "WSO2 Identity Server"
>= 7.0.0.0 < 7.0.0.59
Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 7.0.0.0 < 7.0.0.59"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Open Banking KM
Search vendor "WSO2" for product "WSO2 Open Banking KM"
>= 1.3.0.0 < 1.3.0.114
Search vendor "WSO2" for product "WSO2 Open Banking KM" and version " >= 1.3.0.0 < 1.3.0.114"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Open Banking KM
Search vendor "WSO2" for product "WSO2 Open Banking KM"
>= 1.4.0.0 < 1.4.0.130
Search vendor "WSO2" for product "WSO2 Open Banking KM" and version " >= 1.4.0.0 < 1.4.0.130"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Open Banking KM
Search vendor "WSO2" for product "WSO2 Open Banking KM"
>= 1.5.0.0 < 1.5.0.120
Search vendor "WSO2" for product "WSO2 Open Banking KM" and version " >= 1.5.0.0 < 1.5.0.120"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Open Banking IAM
Search vendor "WSO2" for product "WSO2 Open Banking IAM"
>= 2.0.0.0 < 2.0.0.363
Search vendor "WSO2" for product "WSO2 Open Banking IAM" and version " >= 2.0.0.0 < 2.0.0.363"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.2.2.0 < 5.2.2.14
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.2.2.0 < 5.2.2.14"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.7.5.0 < 5.7.5.15
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.7.5.0 < 5.7.5.15"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.10.86.0 < 5.10.86.5
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.10.86.0 < 5.10.86.5"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.10.112.0 < 5.10.112.16
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.10.112.0 < 5.10.112.16"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.11.148.0 < 5.11.148.15
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.11.148.0 < 5.11.148.15"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.11.256.0 < 5.11.256.17
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.11.256.0 < 5.11.256.17"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.12.153.0 < 5.12.153.59
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.12.153.0 < 5.12.153.59"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.12.387.0 < 5.12.387.42
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.12.387.0 < 5.12.387.42"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.14.97.0 < 5.14.97.76
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.14.97.0 < 5.14.97.76"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.17.5.0 < 5.17.5.284
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.17.5.0 < 5.17.5.284"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.18.187.0 < 5.18.187.268
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.18.187.0 < 5.18.187.268"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.23.8.0 < 5.23.8.186
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.23.8.0 < 5.23.8.186"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 5.25.92.0 < 5.25.92.95
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 5.25.92.0 < 5.25.92.95"
en
Affected
WSO2
Search vendor "WSO2"
WSO2 Carbon Policy Editor BE
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE"
>= 7.0.78.0 < 7.0.78.35
Search vendor "WSO2" for product "WSO2 Carbon Policy Editor BE" and version " >= 7.0.78.0 < 7.0.78.35"
en
Affected