Maven package
org.wso2.am/am-parent
pkg:maven/org.wso2.am/am-parent
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-7096 | — | >= 2.0.0, < 4.4.0 | 4.4.0 | May 30, 2025 | A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible | ||
| CVE-2024-2321 | — | >= 4.2.0-beta, <= 4.2.0 | — | Feb 27, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API | ||
| CVE-2020-13226 | — | <= 3.0.0 | — | May 20, 2020 | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet. |
- CVE-2024-7096May 30, 2025affected >= 2.0.0, < 4.4.0fixed 4.4.0
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible
- CVE-2024-2321Feb 27, 2025affected >= 4.2.0-beta, <= 4.2.0
An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API
- CVE-2020-13226May 20, 2020affected <= 3.0.0
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.