S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 21, 2025

CVE-2024-7097 Scanner

CVE-2024-7097 Scanner - Account Creation vulnerability in WSO2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7097
4.3
CVSSmedium
Exploitable from an adjacent network · no authentication required.

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
Affected
WSO2 Open Banking AMby WSO2
AFFECTED< 1.3.0SAFE ✓≥ 1.3.0
WSO2 Open Banking KMby WSO2
AFFECTED< 1.3.0SAFE ✓≥ 1.3.0
WSO2 Identity Server as Key Managerby WSO2
AFFECTED< 5.3.0SAFE ✓≥ 5.3.0
WSO2 API Managerby WSO2
AFFECTED< 2.0.0SAFE ✓≥ 2.0.0
Updated Aug 22, 2026View on NVD →
Detail

WSO2 is a widely used middleware platform providing various enterprise solutions, including API management, identity management, and integration services. It is primarily used by organizations to manage authentication, user identities, and enterprise service buses efficiently. The platform is designed to streamline digital transformation and enable seamless integration across diverse systems and services. However, any vulnerabilities within this system could have far-reaching consequences for enterprises relying on WSO2's authentication and management services.

The detected vulnerability enables attackers to create arbitrary accounts via the SOAP admin service, bypassing existing self-registration restrictions. This issue stems from improper checks on the configuration settings governing user registrations. By exploiting this vulnerability, malicious actors can create unauthorized accounts without administrative approval, potentially compromising system security.

Technically, the vulnerability arises from a flaw in the UserRegistrationAdminService endpoint of the WSO2 SOAP service. Attackers can craft malicious SOAP requests to invoke the `addUser` action, enabling unauthorized account creation. The vulnerable endpoints do not validate the self-registration configuration properly, leaving systems exposed to exploitation.

If exploited, this vulnerability can result in unauthorized access to sensitive resources by attackers using the arbitrarily created accounts. It could also facilitate privilege escalation if the new accounts are granted elevated permissions. Moreover, the presence of unauthorized accounts undermines the integrity and reliability of the WSO2 platform within the organization.

REFERENCES

Solution Advice
  • Disable unused SOAP services to minimize exposure.
  • Apply the latest patches and updates to WSO2 to address the vulnerability.
  • Implement stricter access controls and authentication mechanisms for admin services.
  • Review and restrict user registration configurations to prevent unauthorized account creation.
  • Regularly monitor system logs to identify suspicious account creation activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.