you are viewing a single comment's thread
view the rest of the comments
[–] 10 points 1 day ago (2 children)

Frankly to suggest that an enterprise firewall would be susceptible to a simple path traversal attack is insane. Unless there's the most embarrassing news story of the decade im missing? That kind of input validation is baked into basically everything these days.

Maybe you'll land input validation using quadruple URL encoded '../' or something but even still I'd doubt that.

So the person who replied to you is 100% correct in what it's about, but it doesn't really explain the comic. Unless it was made in like a decade ago.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 9 points 1 day ago (1 child)

    It's pretty common in a killchain following a server side request forgery since the traffic isn't seem by the WAF.

    Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 1 day ago (1 child)

    It really is not common in the common era.

    E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as "enterprise" to any required insurance, even then.

    Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.

  • source
  • parent
  • hideshow 2 child comments