Monday, 30 December 2024

ColdFusion and USAHERDS web-application Vulnerabilities

 



ColdFusion and USAHERDS web-application Vulnerabilities

 

ColdFusion is an application server. ColdFusion is also a web programming language that allows a web application communicate with various back-end systems.

Using ColdFusion, you can create dynamic web pages that offer user input, database lookups, time of day, or any other criteria you require.

ColdFusion is used by the US Social Security Administration, the Food and Drug Administration, The Kennedy Center, the State Department, and the Fortune 100 websites.

ColdFusion Builder reached the end-of-life, effective Oct 1, 2024.

Vulnerability:

  • v A critical security flaw in ColdFusion such as exploit that could cause an arbitrary file system read.

Recommendation:

ΓΌ The vulnerability has been addressed in ColdFusion 2023 Update 12. Recommended to apply the patches to mitigate potential risks.

USAHERDS, USALIMS, USAPlants, USAFoodSafety, and USAMeals are web applications developed by Acclaim Systems to assist U.S. government agencies in tracking and managing animal health, as well as controlling disease outbreaks, which is part of the AgraGuard product suite, which supports agriculture and food safety operations.

Vulnerability:

  • v This involves the use of hardcoded credentials such as static Validation Key and Decryption Key values, allowing attackers to execute malicious code on the USAHERDS, USALIMS, USAPlants, USAFoodSafety, and USAMeals web applications.

With these keys for the web applications, one can construct a malicious View State that passes the MAC check and will be deserialized by the server. This deserialization can result in the execution of code on the server.

Note

More than 125,000 ColdFusion servers are deployed, ColdFusion is one of the most widely adopted web technologies, and a total of 643,663 websites use ColdFusion, across the globe.

Thursday, 19 December 2024

Apple OS and Interface Security Vulnerabilities

 


Apple OS and Interface Security Vulnerabilities

Apple's operating system for its computers, mobiles, ipads, is called macOS, which was previously known as Mac OS X. It is designed specifically for Apple hardware and provides a user-friendly interface along with various built-in applications. Apple OS Operating system is branded and known for its security features.

The following is a list of operating systems released by Apple Inc. There are six supported software platforms: iOS, iPadOS, watchOS, tvOS, macOS and visionOS.

Vulnerabilities – Operating System:

An app may be able to access sensitive user data, or a malicious app may be able to access private information.

This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2.

Vulnerabilities – User Interface:

An unpredictable user interface issue such as “muting a call while ringing may not result in mute being enabled, or increasing the volume and decreasing the volume will not work as expected and misfunction/bug is identified”.

This issue is fixed in iOS 18.2 and iPadOS 18.2. Security fixes are available for, iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.

Recommendation: 

It is advised to apply the security fixes or keep the Apple OS up-to-date.