The following WSO2 product is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0ac2efb9e7a4e4a89a803d6200fae19000fae19000fae19000fae19000fae190
Found WSO2 product: Vulnerable to CVE-2022-29464
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-21 02:04
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=A90CBF9765ED99F387A6280DA6B0C607; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Sat, 21 Dec 2024 02:04:50 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-19 03:20
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=12A3566E00DD02974A31613F26BA2AB3; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Thu, 19 Dec 2024 03:20:54 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-14 15:45
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=97AB77D4AE766CD919F2B8ADFE9222F9; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Sat, 14 Dec 2024 15:45:34 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-12 18:53
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=2EF728F114F41B43749259EEE1C52743; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Thu, 12 Dec 2024 18:53:22 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-03 05:43
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=A47FF53694D7C7E427707C8355376A32; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Tue, 03 Dec 2024 05:43:42 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-12-01 01:32
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=98 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=32129900DB58750ADED056049F7CA21D; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Sun, 01 Dec 2024 01:32:46 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-11-29 01:27
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=F7D3B446C33260DBC83BA873D765F9B5; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Fri, 29 Nov 2024 01:27:05 GMT Connection: close Content-Length: 0
Open service 13.81.49.52:443 · idp-coll.gewiss.com
2024-11-20 19:09
HTTP/1.1 302 Found Keep-Alive: timeout=5, max=99 Content-Type: text/html;charset=UTF-8 Location: https://idp-coll.gewiss.com/carbon Server: WSO2 Carbon Server Set-Cookie: JSESSIONID=44646BBA487684800D008D32A86730FF; Path=/; Secure; HttpOnly X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Date: Wed, 20 Nov 2024 19:09:55 GMT Connection: close Content-Length: 0