CVE-2022-29464 - CVE House
Back to Database
Status published Critical CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote...

Vulnerability Description

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-29464

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

api manager, enterprise integrator, identity server, identity server analytics, identity server as key manager, open banking am, open banking iam, open banking km
Vulnerable Versions:
2.2.0, 6.2.0, 5.2.0, 5.4.0, 5.4.1, 5.5.0, 5.6.0, 5.3.0, 1.3.0, 2.0.0

Timeline

Official Publish: April 18th, 2022
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.