The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade org.wso2.is:identity-server-parent
to version 7.0.0 or higher.
org.wso2.is:identity-server-parent is an open source Identity and Access Management solution federating and managing identities across both enterprise and cloud service environments.
Affected versions of this package are vulnerable to Incorrect Authorization due to a business logic flaw in SOAP admin services. An attacker can create a new user with elevated permissions by exploiting accessible SOAP admin services, provided the deployment includes an internally used attribute not part of the default WSO2 product configuration and at least one custom role exists with non-default permissions.
Note:
This is only exploitable if SOAP admin services are accessible to the attacker, the deployment includes an internally used attribute that is not part of the default WSO2 product configuration, at least one custom role exists with non-default permissions, and the attacker has knowledge of the custom role and the internal attribute used in the deployment.