Server-Side Request Forgery Vulnerability in WSO2 Products
CVE-2024-7073
Key Information:
- Vendor
Wso2
- Status
- Vendor
- CVE Published:
- 2 June 2025
What is CVE-2024-7073?
A server-side request forgery (SSRF) vulnerability exists in various WSO2 products due to inadequate input validation in SOAP admin services. This security flaw enables unauthenticated attackers to craft malicious requests that manipulate server-side processes. By exploiting this vulnerability, attackers can gain unauthorized access to sensitive data and resources, including those within private networks, enhancing the risk of data breaches and unauthorized system manipulation. It is crucial for users of these WSO2 products to apply recommended security patches and updates to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 Carbon Policy Editor BE 5.2.2 < 5.2.2.14
WSO2 Carbon Policy Editor BE 5.7.5 < 5.7.5.15
WSO2 Carbon Policy Editor BE 5.10.86 < 5.10.86.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
