Cequence Researchers Discover Critical API Security Vulnerability in One of the Largest Food and Drug Retailers’ IT Infrastructure
Vulnerability found by CQ Prime Threat Research team enabled unauthorized users to access and extract sensitive data
SANTA CLARA, Calif. – October 29, 2024 – Cequence Security, a pioneer in API security and bot management, today announced that its CQ Prime Threat Research Team has identified a critical vulnerability within one of the largest food and drug retailers’ IT infrastructure affecting four subdomains. These subdomains inadvertently exposed the actuator endpoint, enabling unauthorized users to access and extract sensitive data, such as root passwords from heap dumps, which offer a snapshot of active objects and potentially sensitive information.
The vulnerability carries a CVSS score of 9.8, signifying the highest possible severity and potential for widespread breaches, underscoring the urgency and importance of its remediation. It was discovered on May 9, 2024, and has since been patched by the retailer’s team with assistance from Cequence.
Exposed Endpoint Provides Backdoor to AppDynamics
The exposed heap dump endpoint included the admin username and password to AppDynamics, a business observability platform that helps organizations monitor and manage the performance of their applications and IT operations. This access allows attackers to extract memory snapshots directly from the server. These snapshots can be analyzed using tools like Visual VM to reveal confidential information, which could then be leveraged to gain unauthorized administrative access to the AppDynamics portal. With such admin access, malicious actors could:- Add and delete employee login access
- Monitor traffic across all applications, including in-store and online retail activity
- Create policies to view or exfiltrate sensitive account information, increasing the risk of data breaches
- Introduce policies that hinder normal operations, disable security measures, or create backdoors for future attacks
- Obtain valid access tokens without proper authorization, allowing them to impersonate legitimate API clients