An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed.
Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.
                
            References
                    | Link | Resource | 
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ | Vendor Advisory | 
Configurations
                    History
                    06 Oct 2025, 13:57
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:* | |
| References | () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/ - Vendor Advisory | |
| First Time | Wso2 Wso2 identity Server | 
23 May 2025, 15:54
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
22 May 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-22 19:15
Updated : 2025-10-06 13:57
NVD link : CVE-2024-7487
Mitre link : CVE-2024-7487
CVE.ORG link : CVE-2024-7487
JSON object : View
Products Affected
                wso2
- identity_server
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
