LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-29464: WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 16, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-29464 to its Known Exploited Vulnerabilities catalog on Apr 25, 2022, with a federal patch deadline of May 16, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

CVE-2022-29464 is an unrestricted file upload weakness affecting multiple WSO2 products. It can allow an attacker to place files on the system in a way that leads to remote code execution. Because the flaw has been tied to known ransomware activity, organizations running WSO2 components should treat it as a high-priority exposure and confirm their exact product versions and configurations against the vendor advisory.

Unrestricted upload flaws of this type matter because WSO2 products are commonly used for identity, API management, and integration services that sit on critical paths. Successful abuse can give an attacker a foothold for further lateral movement or ransomware deployment.

How it works

The vulnerability is tracked under CWE-22 and is described as unrestricted file upload that results in remote code execution. In this class of weakness, the application fails to adequately restrict the location, type, or content of files submitted by a user. An attacker who can reach the upload functionality may supply a crafted file that is written outside the intended directory or that is later interpreted and executed by the server.

Public detail on the precise request format or payload is limited; defenders should not rely on incomplete public descriptions. Confirm the exact attack surface and any required authentication or endpoint paths against the official WSO2 advisory. Once a malicious file is present and executable, the attacker can run arbitrary code in the context of the WSO2 process, which often has broad access to configuration, credentials, and connected systems.

Am I affected? How to find it in your systems

WSO2 products are typically deployed as on-premises or private-cloud middleware for API gateways, identity servers, enterprise service buses, and related integration platforms. Inventory any hosts, containers, or virtual machines running WSO2 software, including development, test, and production instances.

Because the CISA summary states that multiple products are affected, treat any unpatched WSO2 deployment as potentially vulnerable until the vendor matrix confirms otherwise.

How to remediate

The primary remediation is to apply the updates provided by WSO2 exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow that guidance without delay.

If you can't patch immediately

When immediate patching is not possible, apply compensating controls to reduce the attack surface until the vendor update can be installed.

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities that enable remote code execution are frequently used as initial access for ransomware and data theft. If logs or other indicators suggest compromise, isolate the affected systems, preserve forensic evidence, and follow your incident-response plan, including credential rotation and notification obligations. As an additional step, you can run a free exposure scan of your email addresses against known breach data sets to determine whether associated credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWSO2 · Multiple Products
WeaknessCWE-22
Added to CISA KEVApr 25, 2022
Federal patch deadlineMay 16, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities