The following WSO2 product is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0ac2efb9e7a4e4a89a803d6200fae19000fae19000fae19000fae19000fae190
Found WSO2 product: Vulnerable to CVE-2022-29464
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-12-20 23:28
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=A306CBA600C407068F5C688B55899BC4; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Fri, 20 Dec 2024 23:28:20 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-12-18 15:24
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=DDCD767A9B97F2EC75AF657591CA6980; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Wed, 18 Dec 2024 15:24:11 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-12-14 09:04
HTTP/1.0 503 Service Unavailable Cache-Control: no-cache Connection: close Content-Type: text/html <html><body><h1>503 Service Unavailable</h1> No server is available to handle this request. </body></html>
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-12-12 15:43
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=D754AAC2D1342BE0A297FE90D0E78A70; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Thu, 12 Dec 2024 15:44:02 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-11-30 12:25
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=A3627D8627675C9986C94A226395678F; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Sat, 30 Nov 2024 12:25:17 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-11-28 12:03
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=6249B09C30418D6201B544C706CC5CA6; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Thu, 28 Nov 2024 12:03:44 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT
Open service 157.86.211.30:443 · apim2.fiocruz.br
2024-11-20 09:51
HTTP/1.1 302 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=61643C31F01B98F14EA30062899C1A82; Path=/; Secure; HttpOnly Location: https://apim2.fiocruz.br:443/publisher/ Content-Length: 0 Date: Wed, 20 Nov 2024 09:51:50 GMT Connection: close Server: WSO2 Carbon Server Access-Control-Allow-Origin: * Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId Access-Control-Max-Age: 3628800 Access-Control-Allow-Methods: GET, DELETE, OPTIONS, POST, PUT