CVE-2024-7073 Details
Description
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected product.
A server-side request forgery (SSRF) vulnerability has been identified in multiple WSO2 products, including WSO2 Identity Server, WSO2 Open Banking IAM, and WSO2 Open Banking KM. This vulnerability arises from inadequate input validation in SOAP admin services, allowing unauthenticated attackers to manipulate server-side requests. Exploitation could lead to unauthorized access to sensitive data and systems, including resources within private networks, as long as they are reachable by the affected WSO2 product.
Community users can apply the relevant fixes using the public pull request available on GitHub. Commercial users should update to the specified update level for their product version. WSO2 customers with a support subscription can use WSO2 Updates to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3562 | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 identity server | 5.2.0 5.3.0 5.4.0 5.4.1 5.5.0 5.6.0 5.7.0 5.8.0 5.9.0 5.10.0 5.11.0 6.0.0 6.1.0 7.0.0 |
CPE
Remediation
| |
| wso2 identity server as key manager | 5.3.0 5.5.0 5.6.0 5.7.0 5.9.0 5.10.0 |
CPE
Remediation
| |
| wso2 open banking iam | 2.0.0 |
CPE
Remediation
| |
| wso2 open banking km | 1.3.0 1.4.0 1.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Jun 2, 2025 | New CVE Received | WSO2 LLC |