CVE-2024-7074: WSO2 API Manager

Medium severity, CVSS 6.8. EPSS: 17.2% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server. By leveraging this vulnerability, an attacker could upload a specially crafted payload, potentially achieving remote code execution (RCE) on the server. Exploitation requires valid admin credentials, limiting its impact to authorized but potentially malicious users.

Affected products

  • WSO2 WSO2 API Manager: from 2.0.0, before 2.0.0.28 (fixed in 2.0.0.28); from 2.1.0, before 2.1.0.38 (fixed in 2.1.0.38); from 2.2.0, before 2.2.0.57 (fixed in 2.2.0.57); from 2.5.0, before 2.5.0.83 (fixed in 2.5.0.83); from 2.6.0, before 2.6.0.143 (fixed in 2.6.0.143); from 3.0.0, before 3.0.0.162 (fixed in 3.0.0.162); …
  • WSO2 WSO2 Carbon Synapse Artifact Uploader Be: from 4.4.10, before 4.4.10.3 (fixed in 4.4.10.3); from 4.6.1, before 4.6.1.4 (fixed in 4.6.1.4); from 4.6.6, before 4.6.6.9 (fixed in 4.6.6.9); from 4.6.10, before 4.6.10.4 (fixed in 4.6.10.4); from 4.6.16, before 4.6.16.2 (fixed in 4.6.16.2); from 4.6.19, before 4.6.19.10 (fixed in 4.6.19.10); …
  • WSO2 WSO2 Enterprise Integrator: from 6.0.0, before 6.0.0.21 (fixed in 6.0.0.21); from 6.1.0, before 6.1.0.38 (fixed in 6.1.0.38); from 6.1.1, before 6.1.1.42 (fixed in 6.1.1.42); from 6.2.0, before 6.2.0.61 (fixed in 6.2.0.61); from 6.3.0, before 6.3.0.69 (fixed in 6.3.0.69); from 6.4.0, before 6.4.0.96 (fixed in 6.4.0.96); …
  • WSO2 WSO2 Enterprise Mobility Manager: from 2.2.0, before 2.2.0.27 (fixed in 2.2.0.27)
  • WSO2 WSO2 Enterprise Service Bus: from 4.9.0, before 4.9.0.10 (fixed in 4.9.0.10); from 5.0.0, before 5.0.0.28 (fixed in 5.0.0.28)
  • WSO2 WSO2 Micro Integrator: from 1.0.0, before 1.0.0.49 (fixed in 1.0.0.49)
  • WSO2 WSO2 Open Banking AM: from 1.3.0, before 1.3.0.132 (fixed in 1.3.0.132); from 1.4.0, before 1.4.0.135 (fixed in 1.4.0.135); from 1.5.0, before 1.5.0.137 (fixed in 1.5.0.137); from 2.0.0, before 2.0.0.342 (fixed in 2.0.0.342)

Published 2025-06-02. Last modified 2026-06-17.