CVE-2022-29464
랜섬웨어 악용 WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
악용 여부
랜섬웨어 악용
심각도 (발행처 발표값)
심각9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
악용 확률 (EPSS)
100.0%
한국어 공식 권고
CISA 원문
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
CWE-22 CWE-22
악용 확률 변화
| 기준일 | 확률 | 백분위 |
|---|---|---|
| 2026-09-06 | 100.00% | 100.0% |
| 2026-09-05 | 100.00% | 100.0% |
| 2026-09-04 | 100.00% | 100.0% |