Vulnerability Description
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Manager | 2.1.0 |
| Wso2 | Identity Server | 5.2.0 |
| Wso2 | Identity Server As Key Manager | 5.3.0 |
| Wso2 | Open Banking Am | 2.0.0 |
| Wso2 | Open Banking Iam | 2.0.0 |
| Wso2 | Open Banking Km | 1.3.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-7097?
CVE-2024-7097 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration ...
How severe is CVE-2024-7097?
CVE-2024-7097 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7097?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Manager, Wso2 Identity Server, Wso2 Identity Server As Key Manager, Wso2 Open Banking Am, Wso2 Open Banking Iam.