WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
n/a — n/a
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Apr 18, 2022
- Modified
- Jun 17, 2026
- Added to KEV
- Apr 25, 2022
- Federal patch due
- May 16, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2022-29464, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- hakivvi/CVE-2022-29464★ 377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
updated Aug 21, 2026
- dsssssssm/WSOB★ 26
😭 WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
updated Aug 21, 2026
- sh4den/CVE-2022-29464★ 10
A bots loader for CVE-2022-29464 with multithreading
updated Aug 21, 2026
- Ap0dexMe0/CVE-2022-29464★ 9
Perform With Mass Exploits In WSO Management.
updated Mar 1, 2026
- gbrsh/CVE-2022-29464★ 7
RCE exploit for WSO2
updated Jan 4, 2024
- Lidong-io/cve-2022-29464★ 5
cve-2022-29464 批量脚本
updated May 31, 2024
- jimidk/Better-CVE-2022-29464★ 5
CVE-2022-29464 PoC for WSO2 products
updated May 18, 2026
- hev0x/CVE-2022-29464★ 5
WSO2 RCE (CVE-2022-29464)
updated Apr 28, 2025
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2022-29464?
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
How severe is CVE-2022-29464?
CVE-2022-29464 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2022-29464 actively exploited in the wild?
Yes. CVE-2022-29464 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Apr 25, 2022, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2022-29464?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2022-29464?
Yes - a public Nuclei template referencing CVE-2022-29464 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2022-29464?
CVE-2022-29464 is classified under CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Cross-checked against
Impactr finds and proves whether CVE-2022-29464 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist