CVE-2024-7487

A

n improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*

History

06 Oct 2025, 13:57

Type Values Removed Values Added
First Time Wso2
Wso2 identity Server
CPE cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ - Vendor Advisory

23 May 2025, 15:54

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-22 19:15

Updated : 2025-10-06 13:57


NVD link : CVE-2024-7487

Mitre link : CVE-2024-7487

CVE.ORG link : CVE-2024-7487


JSON object : View

Products Affected
CWE
CWE-287

Improper Authentication