Incorrect Authorization Affecting org.wso2.am:am-parent package, versions [2.0.0,4.3.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGWSO2AM-10558110
  • published27 Jun 2025
  • disclosed30 May 2025
  • creditUnknown

Introduced: 30 May 2025

CVE-2024-7096  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade org.wso2.am:am-parent to version 4.3.0 or higher.

Overview

org.wso2.am:am-parent is a WSO2 API Manager - Aggregator Module

Affected versions of this package are vulnerable to Incorrect Authorization due to a business logic flaw in SOAP admin services. An attacker can create a new user with elevated permissions by exploiting accessible SOAP admin services, provided the deployment includes an internally used attribute not part of the default WSO2 product configuration and at least one custom role exists with non-default permissions.

Note:

This is only exploitable if SOAP admin services are accessible to the attacker, the deployment includes an internally used attribute that is not part of the default WSO2 product configuration, at least one custom role exists with non-default permissions, and the attacker has knowledge of the custom role and the internal attribute used in the deployment.

CVSS Base Scores

version 4.0
version 3.1