WSO2 Enterprise Integrator
cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*
- 6.6.0
A vulnerability allowing arbitrary file upload has been identified in multiple WSO2 products, including WSO2 Enterprise Integrator, WSO2 Identity Server, WSO2 Open Banking IAM, and WSO2 Identity Server as Key Manager. This vulnerability arises from inadequate validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. An attacker with administrative privileges can exploit this flaw to upload malicious files to a user-controlled location on the server. By doing so, the attacker could execute remote code, potentially compromising the server and its data.
Exploitation of this vulnerability allows for remote code execution on the server, with the potential to compromise the server and its data.
WSO2 recommends that community users migrate to the latest version of the respective WSO2 products. Support subscription holders should update their product to the specified update level or a higher update level to apply the fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.