Record summary

CVE-2024-7097 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 2, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2025 · Source: CVE List

Affected products and versions

8
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.29affected
2.1.0 to < 2.1.0.39affected
2.2.0 to < 2.2.0.56affected
2.5.0 to < 2.5.0.83affected
2.6.0 to < 2.6.0.142affected
3.0.0 to < 3.0.0.162affected
3.1.0 to < 3.1.0.294affected
3.2.0 to < 3.2.0.384affected
3.2.1 to < 3.2.1.16affected
4.0.0 to < 4.0.0.305affected
4.1.0 to < 4.1.0.166affected
Showing 12 of 14 version ranges

WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager
VulnCheckVersion data not supplied

WSO2 Enterprise Mobility Manager

Browse WSO2 / WSO2 Enterprise Mobility Manager

Default status: unknown

CVE List2.2.0 to < 2.2.0.26affected

Default status: unaffected

CVE ListBefore 5.2.0unknown
5.2.0 to < 5.2.0.32affected
5.3.0 to < 5.3.0.33affected
5.4.0 to < 5.4.0.32affected
5.4.1 to < 5.4.1.36affected
5.5.0 to < 5.5.0.50affected
5.6.0 to < 5.6.0.58affected
5.7.0 to < 5.7.0.123affected
5.8.0 to < 5.8.0.106affected
5.9.0 to < 5.9.0.157affected
5.10.0 to < 5.10.0.318affected
5.11.0 to < 5.11.0.365affected
Showing 12 of 15 version ranges

WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 Identity Server as Key Manager

Default status: unaffected

CVE ListBefore 5.3.0unknown
5.3.0 to < 5.3.0.38affected
5.5.0 to < 5.5.0.51affected
5.6.0 to < 5.6.0.72affected
5.7.0 to < 5.7.0.122affected
5.9.0 to < 5.9.0.165affected
5.10.0 to < 5.10.0.312affected

Default status: unaffected

CVE ListBefore 1.3.0unknown
1.3.0 to < 1.3.0.131affected
1.4.0 to < 1.4.0.134affected
1.5.0 to < 1.5.0.136affected
2.0.0 to < 2.0.0.343affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.364affected

Default status: unaffected

CVE ListBefore 1.3.0unknown
1.3.0 to < 1.3.0.114affected
1.4.0 to < 1.4.0.130affected
1.5.0 to < 1.5.0.120affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWSO2 User Registration - Arbitrary Account Creation

The SOAP admin service in WSO2 products has a security vulnerability that allows the creation of new user accounts regardless of the self-registration configuration settings.

Impact

Unauthenticated attackers can bypass self-registration restrictions to create arbitrary user accounts, potentially gaining unauthorized access to the WSO2 system and its resources.

Remediation

Apply security patches from WSO2 as outlined in security advisory WSO2-2024-3574 to address the arbitrary account creation vulnerability.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024wso2intrusiveauth-bypassvkevvuln
Shodan: WSO2 Carbon Server

Source: ProjectDiscovery

References

2