The following WSO2 product is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0ac2efb9e7a4e4a89a803d6200fae19000fae19000fae19000fae19000fae190
Found WSO2 product: Vulnerable to CVE-2022-29464
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-20 23:35
HTTP/1.1 302 Found Date: Fri, 20 Dec 2024 23:35:30 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=8487E80658F5D915F3395BA65AC2A100; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-18 14:51
HTTP/1.1 302 Found Date: Wed, 18 Dec 2024 14:52:02 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=3D39FF82936CD88D5929588198E4F4F8; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-16 04:57
HTTP/1.1 302 Found Date: Mon, 16 Dec 2024 04:57:19 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=A98C99FFF239F288D52A9FCEB4DEC678; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-14 06:34
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 06:34:53 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=41DD5BA90A9F2B8A3001D876DAC2C7FD; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-12 06:50
HTTP/1.1 302 Found Date: Thu, 12 Dec 2024 06:50:17 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=C8367DC51ECBB363CF20E4E6BCA63C8A; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-12-02 17:42
HTTP/1.1 302 Found Date: Mon, 02 Dec 2024 17:42:28 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=40B10E72A8AAC7D3CFE9CE9021B7BB3F; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-11-30 14:56
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 14:56:32 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=2BFE6B92AE969DBB7F6632629B41F213; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-11-28 19:17
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 19:17:08 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=B4A61DBDF13445991F5BC7368D85A3BF; Path=/; Secure; HttpOnly set-cookie: SRV=84214f56-0cd8-4fd0-b475-02a57b7c209b; path=/ Connection: close
Open service 194.5.170.186:443 · portail.api.preprod.din.developpement-durable.gouv.fr
2024-11-20 23:13
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 23:13:14 GMT Server: WSO2 Carbon Server Strict-Transport-Security: max-age=31536000 content-length: 0 location: https://portail.api.preprod.din.developpement-durable.gouv.fr:443/publisher/ x-content-type-options: nosniff set-cookie: JSESSIONID=2BF65B2A65E23BB903DF664BA3F917CB; Path=/; Secure; HttpOnly set-cookie: SRV=f2cc8805-c67e-4822-b415-9060b69c8ad6; path=/ Connection: close