VYPR
Medium severity5.8NVD Advisory· Published May 22, 2025· Updated Jun 17, 2026

CVE-2024-7487

CVE-2024-7487

Description

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.

Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • WSO2/WSO2 Identity Serverv5
    Range: 7.0.0
  • WSO2/Client Attestation Filterv5
    Range: 7.0.26
  • WSO2/WSO2 Carbon Identity Client Attestation Met Data Mgt BEv5
    Range: 7.0.78

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.