Maven package
org.wso2.is/identity-server-parent
pkg:maven/org.wso2.is/identity-server-parent
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-7096 | — | >= 5.2.0, < 7.1.0 | 7.1.0 | May 30, 2025 | A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible | ||
| CVE-2024-2321 | — | >= 6.1.0-beta, <= 6.1.0 | — | Feb 27, 2025 | An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API |
- CVE-2024-7096May 30, 2025affected >= 5.2.0, < 7.1.0fixed 7.1.0
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible
- CVE-2024-2321Feb 27, 2025affected >= 6.1.0-beta, <= 6.1.0
An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API