CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Record summary
CVE-2024-7097 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 2, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2025 · Source: CVE List
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.29 | affected | ||
| 2.1.0 to < 2.1.0.39 | affected | ||
| 2.2.0 to < 2.2.0.56 | affected | ||
| 2.5.0 to < 2.5.0.83 | affected | ||
| 2.6.0 to < 2.6.0.142 | affected | ||
| 3.0.0 to < 3.0.0.162 | affected | ||
| 3.1.0 to < 3.1.0.294 | affected | ||
| 3.2.0 to < 3.2.0.384 | affected | ||
| 3.2.1 to < 3.2.1.16 | affected | ||
| 4.0.0 to < 4.0.0.305 | affected | ||
| 4.1.0 to < 4.1.0.166 | affected | ||
| Showing 12 of 14 version ranges | |||
WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager | VulnCheck | Version data not supplied | |
WSO2 Enterprise Mobility ManagerBrowse WSO2 / WSO2 Enterprise Mobility ManagerDefault status: unknown | CVE List | 2.2.0 to < 2.2.0.26 | affected |
WSO2 Identity ServerBrowse WSO2 / WSO2 Identity ServerDefault status: unaffected | CVE List | Before 5.2.0 | unknown |
| 5.2.0 to < 5.2.0.32 | affected | ||
| 5.3.0 to < 5.3.0.33 | affected | ||
| 5.4.0 to < 5.4.0.32 | affected | ||
| 5.4.1 to < 5.4.1.36 | affected | ||
| 5.5.0 to < 5.5.0.50 | affected | ||
| 5.6.0 to < 5.6.0.58 | affected | ||
| 5.7.0 to < 5.7.0.123 | affected | ||
| 5.8.0 to < 5.8.0.106 | affected | ||
| 5.9.0 to < 5.9.0.157 | affected | ||
| 5.10.0 to < 5.10.0.318 | affected | ||
| 5.11.0 to < 5.11.0.365 | affected | ||
| Showing 12 of 15 version ranges | |||
WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 Identity Server as Key ManagerDefault status: unaffected | CVE List | Before 5.3.0 | unknown |
| 5.3.0 to < 5.3.0.38 | affected | ||
| 5.5.0 to < 5.5.0.51 | affected | ||
| 5.6.0 to < 5.6.0.72 | affected | ||
| 5.7.0 to < 5.7.0.122 | affected | ||
| 5.9.0 to < 5.9.0.165 | affected | ||
| 5.10.0 to < 5.10.0.312 | affected | ||
WSO2 Open Banking AMBrowse WSO2 / WSO2 Open Banking AMDefault status: unaffected | CVE List | Before 1.3.0 | unknown |
| 1.3.0 to < 1.3.0.131 | affected | ||
| 1.4.0 to < 1.4.0.134 | affected | ||
| 1.5.0 to < 1.5.0.136 | affected | ||
| 2.0.0 to < 2.0.0.343 | affected | ||
WSO2 Open Banking IAMBrowse WSO2 / WSO2 Open Banking IAMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.364 | affected | ||
WSO2 Open Banking KMBrowse WSO2 / WSO2 Open Banking KMDefault status: unaffected | CVE List | Before 1.3.0 | unknown |
| 1.3.0 to < 1.3.0.114 | affected | ||
| 1.4.0 to < 1.4.0.130 | affected | ||
| 1.5.0 to < 1.5.0.120 | affected | ||
Nuclei templates
1ProjectDiscoveryMEDIUMWSO2 User Registration - Arbitrary Account Creation
The SOAP admin service in WSO2 products has a security vulnerability that allows the creation of new user accounts regardless of the self-registration configuration settings.
Impact
Unauthenticated attackers can bypass self-registration restrictions to create arbitrary user accounts, potentially gaining unauthorized access to the WSO2 system and its resources.
Remediation
Apply security patches from WSO2 as outlined in security advisory WSO2-2024-3574 to address the arbitrary account creation vulnerability.
Source: ProjectDiscovery