β² 271 βΌ can someone explain this to me? π«ͺ (thelemmy.club) submitted 1 day ago by not_IO@lemmy.blahaj.zone to c/linuxmemes@lemmy.world 22 comments fedilink hide all child comments
[β] helvetpuli@sopuli.xyz 9 points 1 day ago (1 child) It's pretty common in a killchain following a server side request forgery since the traffic isn't seem by the WAF. Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882 permalink fedilink source parent hideshow 2 child comments replies: [β] foggy@lemmy.world 2 points 1 day ago (1 child) It really is not common in the common era. E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as "enterprise" to any required insurance, even then. Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday. permalink fedilink source parent hideshow 2 child comments replies: [β] helvetpuli@sopuli.xyz 1 point 6 hours ago Of course it isn't. It was behind a WAF. But that didn't matter for the path traversal in this attack. permalink fedilink source parent
[β] foggy@lemmy.world 2 points 1 day ago (1 child) It really is not common in the common era. E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as "enterprise" to any required insurance, even then. Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday. permalink fedilink source parent hideshow 2 child comments replies: [β] helvetpuli@sopuli.xyz 1 point 6 hours ago Of course it isn't. It was behind a WAF. But that didn't matter for the path traversal in this attack. permalink fedilink source parent
[β] helvetpuli@sopuli.xyz 1 point 6 hours ago Of course it isn't. It was behind a WAF. But that didn't matter for the path traversal in this attack. permalink fedilink source parent