← Back to the feed

~/article/pre-auth-rce-in-enterprise-java-hits-bonita-and-ofbiz-servers-12vam8
highSource: Help Net Security

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability…

Read at the source

Summary written for cymesh.dev. The full article lives at Help Net Security.

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/pre-auth-rce-in-enterprise-java-hits-bonita-and-ofbiz-servers-12vam8