The following WSO2 product is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0ac2efb9e7a4e4a89a803d6200fae19000fae19000fae19000fae19000fae190
Found WSO2 product: Vulnerable to CVE-2022-29464
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-12-21 01:46
HTTP/1.1 302 Date: Sat, 21 Dec 2024 01:46:58 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=F5C6322BF392D340394A23BA12A25837; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-12-19 01:29
HTTP/1.1 302 Date: Thu, 19 Dec 2024 01:29:05 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=A1AE6CA1CF036BDD1470DB3A68658B95; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-12-12 18:52
HTTP/1.1 302 Date: Thu, 12 Dec 2024 18:52:28 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=C7C8BCA68944C46C761BD1DBE977D22F; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-12-03 05:47
HTTP/1.1 302 Date: Tue, 03 Dec 2024 05:48:01 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=51A42D066C6D2B3D3015076E1747F811; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-12-01 00:35
HTTP/1.1 302 Date: Sun, 01 Dec 2024 00:36:00 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=555f0c2a66fe38d1c0bed634dd328261; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=555f0c2a66fe38d1c0bed634dd328261; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=34BCDF572EDB5566C079C7D8584361D2; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-11-28 14:08
HTTP/1.1 302 Date: Thu, 28 Nov 2024 14:08:02 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=F9C38F21A76E6ACD4D75B64108C50131; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server
Open service 20.126.186.80:443 · soa.dev.motul.com
2024-11-20 09:36
HTTP/1.1 302 Date: Wed, 20 Nov 2024 09:36:20 GMT Content-Length: 0 Connection: close Set-Cookie: ApplicationGatewayAffinityCORS=68fb7f1807ce1a3f57268ddd04c80a82; Path=/; SameSite=None; Secure Set-Cookie: ApplicationGatewayAffinity=68fb7f1807ce1a3f57268ddd04c80a82; Path=/ X-Frame-Options: DENY X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Set-Cookie: JSESSIONID=9756CC9121DF3EAA4C4A0CF6F6302590; Path=/; Secure; HttpOnly Location: https://soa.dev.motul.com/carbon Server: WSO2 Carbon Server