U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-8995

Change History

Initial Analysis by NIST 8/10/2026 3:07:25 PM

Action Type Old Value New Value
Added CPE Configuration

                  
                
              
OR
          *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.56
          *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.20
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 3.1.0 up to (excluding) 3.1.0.320
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 3.2.0 up to (excluding) 3.2.0.413
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 3.2.1 up to (excluding) 3.2.1.90
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.0.0.334
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.1.0 up to (excluding) 4.1.0.255
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.0.195
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (excluding) 4.3.0.106
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.4.0 up to (excluding) 4.4.0.70
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.55
          *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.19
          *cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* versions from (including) 5.10.0 up to (excluding) 5.10.338
          *cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* versions from (including) 5.11.0 up to (excluding) 5.11.0.395
          *cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.0.0.229
          *cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* versions from (including) 6.1.0 up to (excluding) 6.1.0.208
          *cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:* versions from (including) 5.10.0 up to (excluding) 5.10.0.338
          *cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.0.0.369
          *cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.0.0.389
          *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.54
          *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.19
          *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.55
          *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.19
Added Reference Type

                  
                
              
WSO2 LLC: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-2753/ Types: Vendor Advisory