CVE-2024-7097
MEDIUMDescription
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.
Is your site exposed to CVE-2024-7097?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | api_manager |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server |
| wso2 | identity_server_as_key_manager |
| wso2 | identity_server_as_key_manager |
| wso2 | identity_server_as_key_manager |
| wso2 | identity_server_as_key_manager |
| wso2 | identity_server_as_key_manager |
| wso2 | identity_server_as_key_manager |
| wso2 | open_banking_am |
| wso2 | open_banking_iam |
| wso2 | open_banking_km |
| wso2 | open_banking_km |
| wso2 | open_banking_km |
References
Frequently Asked Questions
What is CVE-2024-7097? +
How severe is CVE-2024-7097? +
What products are affected by CVE-2024-7097? +
How do I check if I'm vulnerable to CVE-2024-7097? +
Related Vulnerabilities
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version …
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. …
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization …
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 …