Issue 80: API vulnerabilities IBM DRM and Cisco USC ☎️

The Latest API Security News, Vulnerabilities and Best Practices
Issue: #80
API vulnerabilities IBM Data Risk Manager and Cisco Unified Computing System
This week, API vulnerabilities have been reported in IBM and Cisco products, and some conferences and webinars related to API security are coming up soon.
Vulnerability: IBM Data Risk Manager
 

Pedro Ribeiro found a bunch of security vulnerabilities in IBM Data Risk Manager (IDRM). This is a control center that helps to locate, analyze, and visualize data-related business risks, so something you would like to be risk-free in itself.

For some internal process reason, IBM refused to accept Ribeiro’s report so the information got published online and the exploit details are now publicly available. To IBM’s credit, they did release a patch within hours. of this happening.

Ribeiro found several critical vulnerabilities in IDRM:

  • Authentication bypass:
    • Lack of input validation and a logic flaw allowed  GET /albatross/saml/idpSelection?id=SOMETHING&userName=admin to associate arbitrary session ID with any existing user without any authentication checks.
    • POST /albatross/user/login accepted username and session ID as parameters, and if the user existed and the session ID was associated with the record, the API returned a newly generated random password for that username.
    • Combined, these flaws allowed attackers to take over any existing account, including administrator accounts.
  • Command Injection:
    • /albatross/restAPI/v2/nmap/run/scan allowed to execute nmap scans, including executing script files.
    • POST /albatross/upload/patch allowed arbitrary file uploads.
    • Both of these required authentication as an administrator, but combined with the authentication bypass vulnerability, that was not a problem.
  • Insecure default password:
    • This one is not REST API-related, but the virtual appliance had hardcoded SSH credentials. However, combined with the two previous API vulnerabilities, this allowed remote code execution as root.
  • Arbitrary file download:
    • POST /albatross/eurekaservice/fetchLogFiles did not properly validate the parameter logFileNameList, so by moving up the directory with ..\ attackers could download any file from the server.

All in all, pretty serious stuff.

Vulnerability: Cisco Unified Computing System
 

Cisco has patched a lot of REST API vulnerabilities in their Unified Computing System (UCS) products UCS Director and UCS Director Express for Big Data.

Most issues were caused by insufficient validation of user-supplied input. As result, the patched vulnerabilities included, to list but a few:

  • Unauthorized administrative access
  • Directory traversal
  • Remote code execution
  • Authentication bypass
  • Denial-of-service (DoS) attacks

To make matters worse, Cisco UCS architecture is integrated in the Epic EHR. There might be potential breaches lurking in the healthcare sector if the institutions don’t patch their systems quickly enough.

APIs need to be designed with zero trust approach in mind. All inputs need to be thoroughly defined and validated.

We have covered previous API security issues in Cisco products in our newsletters 30424346475155, 65, and 69.

Webinar: The Anatomy of 4 API Breaches
 

Learning from others’ mistakes is the best way to learn about security.

On April 30, Isabelle Mauny is hosting a webinar that covers four recent high-profile API security breaches in detail. She will dissect each vulnerability, how and why it happened, and what you can do to prevent similar exploits on your APIs.

If you ever wanted real-life examples on API security dos and don’ts, now is your chance.

Conference: IIoT World 2020
 

Conferences are all going virtual (at least the ones not getting indefinitely rescheduled or canceled).

Industrial IoT World 2020 will be taking place online June 30—July 1, and includes a variety of IoT topics, including security.

You can find the conference agenda here. Registration is free until June 8.

 
dmitry_apisec-1  

Dmitry Sotnikov

APIsecurity.io

 
Thanks for reading.

That's it for today. If you have any feedback or stories to share, simply reply to this email.

Please forward the newsletter to your friends and colleagues who might benefit from it.

 
42Crunch Ltd   71-75 Shelton Street  Covent Garden  London  Greater London   WC2H 9JQ   United Kingdom
You received this email because you are subscribed to API Security News from 42Crunch Ltd.

Update your to choose the types of emails you receive or   
 
 

Older messages

Issue 79: 1.4 million doctor records scraped using API 👩‍⚕️

Thursday, April 16, 2020

Hi, this week we look at recent vulns at GitLab and findadoctor.com, conference talk APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #79 1.4 million doctor

Issue 78: Vulnerabilities in WordPress Rank Math, Tapplock, and TicTocTrack ⌚

Thursday, April 9, 2020

Hi, this week we look into details of 3 API vulnerabilities and SAST for composite OAS APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #78 Vulnerabilities in

You Might Also Like

Ranked | Visualizing Major Asset Class Returns in 2024 📈

Wednesday, January 8, 2025

From bitcoin to the US dollar, asset class returns in 2024 were stellar, in a year marked by elevated rates and a robust US economy. View Online | Subscribe | Download Our App FEATURED STORY

Spyglass Dispatch: Meta Miscues

Wednesday, January 8, 2025

Meta's Social AI Content • Anthropic at $60B • Bluesky at $700M • Dick Wolf's 30 Minute Show • NVIDIA's CPU Aspirations The Spyglass Dispatch is a newsletter sent on weekdays featuring

Top Tech Deals 💰 Anker Power Station, GoPro, 8BitDo Controller, and More!

Wednesday, January 8, 2025

Upgrade your life with a new power station, Wi-Fi 7 router, or AirTags at a big discount. How-To Geek Logo January 8, 2025 Top Tech Deals: Anker Power Station, GoPro Hero, 8BitDo Controller, and More!

Is Claude.ai worth $60 billion? 🎩

Wednesday, January 8, 2025

+ AI will mow my lawn ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏

Post from Syncfusion Blogs on 01/08/2025

Wednesday, January 8, 2025

New blogs from Syncfusion Effortlessly Manage Large File Uploads with Blazor File Manager By Keerthana Rajendran This blog explains the new chunk upload feature added in the Blazor File Manger

⚙️ Waymo's big moment

Wednesday, January 8, 2025

The road to AGI ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

The best AI tech of CES 2025

Wednesday, January 8, 2025

✨ A Linux desktop for AI devs; OTC CGMs; Big Delta upgrades -- ZDNET ZDNET Tech Today - US January 8, 2025 Robotics and AI tech at CES 2025 shown on a universe colorful background. The best robotics

[Guide] AWS Security Essentials in Two Steps

Wednesday, January 8, 2025

Download the quick guide and take control of your AWS security now! The Hacker News The best AWS environments benefit from layered security and smart automation. Securing AWS environments is crucial

FCC Launches 'Cyber Trust Mark' for IoT Devices to Certify Security Compliance

Wednesday, January 8, 2025

THN Daily Updates Newsletter cover Generative AI, Cybersecurity, and Ethics ($88.00 Value) FREE for a Limited Time Equips readers with the skills and insights necessary to succeed in the rapidly

The Sequence Engineering #464: OpenAI’s Relatively Unknown Agent Framework

Wednesday, January 8, 2025

OpenAI Swarm provides the key building blocks for implementing agents. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏