S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-7097

4.3
CVSSmedium
Exploitable from an adjacent network · no authentication required.
Description

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
wso2 open banking amwso2 open banking kmwso2 identity server as key managerwso2 api managerwso2 identity serverwso2 open banking iam
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: wso2 open banking am

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →