BDU:2022-02512CriticalConfirmedExploit available
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Share link
Anyone with the link can open this vulnerability.
Уязвимость платформы для интеграции интерфейсов прикладного программирования, приложений и веб-служб WSO2 связана с возможностью загрузки п…
CVSS
9.8
Critical
EPSS
0.00
p0
Published
2022-01-01
Updated
2022-01-01
Description
Уязвимость платформы для интеграции интерфейсов прикладного программирования, приложений и веб-служб WSO2 связана с возможностью загрузки произвольного JSP-файла на сервер. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код
Tags · CWE
Pre-auth
Affected products
Wso2 Wso2 api managerWso2 Wso2 enterprise integratorWso2 Wso2 identity serverWso2 Wso2 identity server analyticsWso2 Wso2 identity server analyticsWso2 Wso2 identity server analyticsWso2 Wso2 identity server analyticsWso2 Wso2 identity server as key manager
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
BDU:2022-02512
bdu_exploit · https://bdu.fstec.ru/vul
CVE-2022-29464
github-poc · https://github.com/c1ph3rbyt3/CVE-2022-29464
Affected software
| Product | Vendor | Status |
|---|---|---|
| wso2 api manager | wso2 | Tracked |
| wso2 enterprise integrator | wso2 | Tracked |
| wso2 identity server | wso2 | Tracked |
| wso2 identity server analytics | wso2 | Tracked |
| wso2 identity server analytics | wso2 | Tracked |
| wso2 identity server analytics | wso2 | Tracked |
| wso2 identity server analytics | wso2 | Tracked |
| wso2 identity server as key manager | wso2 | Tracked |
Source databases
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Related vulnerabilities