Medium severity5.8NVD Advisory· Published May 22, 2025· Updated Jun 17, 2026
CVE-2024-7487
CVE-2024-7487
Description
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.
Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WSO2/WSO2 Identity Serverv5Range: 7.0.0
- WSO2/Client Attestation Filterv5Range: 7.0.26
- WSO2/WSO2 Carbon Identity Client Attestation Met Data Mgt BEv5Range: 7.0.78
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.