The following WSO2 product is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0ac2efb9e7a4e4a89a803d6200fae19000fae19000fae19000fae19000fae190
Found WSO2 product: Vulnerable to CVE-2022-29464
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-20 23:53
HTTP/1.1 302 Found Date: Fri, 20 Dec 2024 23:53:14 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=262A06CA3FA4F5CF812D0712ED8362B1; Path=/; Secure; HttpOnly set-cookie: SRV=1208cfe7-27ec-4da5-9394-c5ad02c57530; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-19 03:48
HTTP/1.1 302 Found Date: Thu, 19 Dec 2024 03:48:34 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=F454335CEB2AD1BB4DC82A452CA2BAEE; Path=/; Secure; HttpOnly set-cookie: SRV=bc50b681-6830-4791-aace-4d1742a26c00; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-17 20:10
HTTP/1.1 302 Found Date: Tue, 17 Dec 2024 20:10:45 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=53FED1B5D5657610231F89A89801C1CE; Path=/; Secure; HttpOnly set-cookie: SRV=1208cfe7-27ec-4da5-9394-c5ad02c57530; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-14 06:14
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 06:14:57 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=642DFF368B6A6CBB4929A17C437CEF9A; Path=/; Secure; HttpOnly set-cookie: SRV=bc50b681-6830-4791-aace-4d1742a26c00; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-12 09:41
HTTP/1.1 302 Found Date: Thu, 12 Dec 2024 09:41:41 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=5BE1B35BBCF479E2CDB99C03879E8028; Path=/; Secure; HttpOnly set-cookie: SRV=1208cfe7-27ec-4da5-9394-c5ad02c57530; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-12-03 00:41
HTTP/1.1 302 Found Date: Tue, 03 Dec 2024 00:41:32 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=CF6541CABCDB561BBCED2F725F3D881A; Path=/; Secure; HttpOnly set-cookie: SRV=1208cfe7-27ec-4da5-9394-c5ad02c57530; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-11-30 12:25
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 12:25:49 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=137B9420D66228CD085873F3E2F17FD7; Path=/; Secure; HttpOnly set-cookie: SRV=1208cfe7-27ec-4da5-9394-c5ad02c57530; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-11-28 08:35
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 08:35:43 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=2CDA87B3C16F28F6BF05566D63AB5688; Path=/; Secure; HttpOnly set-cookie: SRV=bc50b681-6830-4791-aace-4d1742a26c00; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.din.developpement-durable.gouv.fr
2024-11-20 22:28
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 22:28:58 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=79375C905EBAB3B66465F462ADFFE6FE; Path=/; Secure; HttpOnly set-cookie: SRV=bc50b681-6830-4791-aace-4d1742a26c00; path=/ Connection: close