WSO2 Products Arbitrary File Upload Vulnerability Leading to Remote Code Execution

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in multiple WSO2 products, including WSO2 Enterprise Integrator, WSO2 Identity Server, WSO2 Open Banking IAM, and WSO2 Identity Server as Key Manager. This vulnerability arises from inadequate validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. An attacker with administrative privileges can exploit this flaw to upload malicious files to a user-controlled location on the server. By doing so, the attacker could execute remote code, potentially compromising the server and its data.

Impact

Exploitation of this vulnerability allows for remote code execution on the server, with the potential to compromise the server and its data.

Remediation

WSO2 recommends that community users migrate to the latest version of the respective WSO2 products. Support subscription holders should update their product to the specified update level or a higher update level to apply the fix.

Added: Sep 26, 2025, 10:17 AM
Updated: Sep 26, 2025, 3:45 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
5.0
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.