CVE-2022-29464

Source
https://cve.org/CVERecord?id=CVE-2022-29464
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29464.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-29464
Published
2022-04-18T00:00:00Z
Modified
2026-07-15T01:49:05.094758637Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N CVSS Calculator
Summary
[none]
Details

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29464.json"
}
References

Affected packages

Git / github.com/wso2/product-apim

Affected ranges

Type
GIT
Repo
https://github.com/wso2/product-apim
Events
Database specific
{
    "cpe": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.2.0"
        },
        {
            "last_affected": "4.0.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

4.*
4.0.0-beta
v2.*
v2.2.0
v2.2.0-update1
v2.2.0-update2
v2.2.0-update3
v2.2.0-update4
v2.2.0-update5
v2.2.0-update6
v2.2.0-update7
v2.5.0
v2.5.0-Alpha
v2.5.0-Beta
v2.5.0-rc1
v2.5.0-rc2
v2.5.0-rc3
v2.5.0-rc4
v2.6.0
v2.6.0-alpha
v2.6.0-alpha2
v2.6.0-beta
v2.6.0-beta2
v2.6.0-m1
v2.6.0-m2
v2.6.0-rc1
v2.6.0-rc2
v2.6.0-rc3
v3.*
v3.0.0
v3.0.0-alpha
v3.0.0-alpha2
v3.0.0-beta
v3.0.0-m32
v3.0.0-m33
v3.0.0-m34
v3.0.0-m35
v3.0.0-rc1
v3.0.0-rc2
v3.0.0-rc3
v3.1.0
v3.1.0-alpha
v3.1.0-beta
v3.1.0-m1
v3.1.0-m2
v3.1.0-m3
v3.1.0-m4
v3.1.0-m5
v3.1.0-rc1
v3.1.0-rc2
v3.1.0-rc3
v3.2.0
v3.2.0-alpha
v3.2.0-beta
v3.2.0-m1
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.2.0-rc4
v3.2.0-rc5
v3.2.0-rc6
v4.*
v4.0.0
v4.0.0-alpha
v4.0.0-beta
v4.0.0-m1
v4.0.0-m2
v4.0.0-m3
v4.0.0-m4
v4.0.0-m5
v4.0.0-m6
v4.0.0-m7
v4.0.0-m8
v4.0.0-rc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29464.json"

Git / github.com/wso2/product-ei

Affected ranges

Type
GIT
Repo
https://github.com/wso2/product-ei
Events
Database specific
{
    "cpe": "cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.2.0"
        },
        {
            "last_affected": "6.6.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v6.*
v6.2.0
v6.2.0-rc2
v6.3.0
v6.3.0-m1
v6.3.0-m10
v6.3.0-m11
v6.3.0-m2
v6.3.0-m3
v6.3.0-m4
v6.3.0-m5
v6.3.0-m6
v6.3.0-m7
v6.3.0-m8
v6.3.0-m9
v6.3.0-rc1
v6.3.0-rc2
v6.4.0
v6.4.0-m1
v6.4.0-m2
v6.4.0-m3
v6.4.0-m4
v6.4.0-m5
v6.4.0-m6
v6.4.0-m7
v6.4.0-m8
v6.4.0-rc1
v6.5.0
v6.5.0-m1
v6.5.0-m2
v6.5.0-m3
v6.5.0-m4
v6.5.0-m6
v6.5.0-rc1
v6.6.0
v6.6.0-beta
v6.6.0-rc1
v6.6.0-rc2
v6.6.0-rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29464.json"