VendorsWSO2open_banking_iam2.0.0
Vulnerabilities

WSO2 Open Banking IAM 2.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2025-10611
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Published 2025-10-16 · Analyzed
9.8EPSS 0.008
CVE-2024-6914
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
Published 2025-05-22 · Analyzed
9.8EPSS 0.007
CVE-2025-9312
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
Published 2025-11-18 · Analyzed
9.8EPSS 0.002
CVE-2025-9804
Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
Published 2025-10-16 · Analyzed
9.6EPSS 0.006
CVE-2025-10713
XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
Published 2025-11-05 · Analyzed
9.1EPSS 0.004
CVE-2025-6670
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
Published 2025-11-18 · Analyzed
8.8EPSS 0.002
CVE-2025-10907
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
8.4EPSS 0.006
CVE-2024-6832
Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
Published 2026-08-06 · Analyzed
7.5EPSS 0.004
CVE-2025-3125
Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
7.2EPSS 0.008
CVE-2025-1862
Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code Execution
Published 2025-09-26 · Analyzed
7.2EPSS 0.005
CVE-2025-0663
Potential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-Login
Published 2025-09-23 · Analyzed
6.8EPSS 0.002
CVE-2024-7073
Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin Services
Published 2025-06-02 · Analyzed
6.5EPSS 0.002
CVE-2025-10853
Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output Encoding
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-5350
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
Published 2025-10-24 · Analyzed
5.9EPSS 0.006
CVE-2024-10302
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Published 2026-08-06 · Undergoing Analysis
5.8EPSS 0.003
CVE-2024-7096
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
Published 2025-05-30 · Modified
5.4EPSS 0.007
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Published 2025-10-24 · Analyzed
5.3EPSS 0.009
CVE-2025-1396
Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled
Published 2025-09-26 · Analyzed
5.3EPSS 0.003
CVE-2024-8008
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation
Published 2025-06-02 · Analyzed
5.2EPSS 0.005
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Published 2025-05-30 · Analyzed
4.3EPSS 0.007
CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Published 2025-06-23 · Analyzed
4.3EPSS 0.002
CVE-2025-0672
Authentication Bypass in Multiple WSO2 Products via Stale FIDO Credential Association
Published 2025-09-23 · Analyzed
3.8EPSS 0.002