VYPR

Maven package

org.wso2.is/identity-server-parent

pkg:maven/org.wso2.is/identity-server-parent

Vulnerabilities (2)

  • CVE-2024-7096May 30, 2025
    affected >= 5.2.0, < 7.1.0fixed 7.1.0

    A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible

  • CVE-2024-2321Feb 27, 2025
    affected >= 6.1.0-beta, <= 6.1.0

    An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API