WSO2 API Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*
- 4.6.0
- 4.5.0
- 4.4.0
- 4.3.0
- 4.2.0
A vulnerability exists in multiple WSO2 products, including WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, all in versions 4.6.0 and 4.5.0. This vulnerability allows an authenticated user with administrative privileges to upload arbitrary files to user-controlled locations within the deployment via a system REST API. Such uploads could be exploited to execute remote code.
Exploitation of this vulnerability could result in remote code execution on the affected system.
Community users should apply the public fix available on the WSO2 GitHub repository or migrate to the latest unaffected version. WSO2 support subscription holders can update to the specified update levels for their product version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.