Vulnerability Intelligence Report
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| wso2 | api_manager | all |
| wso2 | enterprise_integrator | all |
| wso2 | identity_server | all |
| wso2 | identity_server_analytics | 5.4.0, 5.4.1, 5.5.0, 5.6.0 |
| wso2 | identity_server_as_key_manager | all |
| wso2 | open_banking_am | all |
| wso2 | open_banking_iam | 2.0.0 |
| wso2 | open_banking_km | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.999%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-04-18T00:00:00 |
| Published | 2022-04-18T00:00:00 |
| Last Updated | 2025-10-21T23:15:41 |
Community Chatter & Buzz