Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Thousands of Oracle NetSuite sites are at risk of exposing customer information
Global Security

Thousands of Oracle NetSuite sites are at risk of exposing customer information

AdminBy AdminAugust 20, 2024No Comments3 Mins Read
Oracle NetSuite Sites
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


August 20, 2024Ravi LakshmananEnterprise Security / Data Breach

Oracle NetSuite Sites

Cybersecurity researchers are warning of the discovery of thousands of third-party Oracle NetSuite e-commerce sites that have been found to be vulnerable to leaking sensitive customer information.

“A potential issue in the NetSuite SuiteCommerce platform could allow attackers to gain access to sensitive data due to misconfiguration of access controls for custom record types (CRTs),” Aaron Costello of AppOmni said.

It should be emphasized here that the problem is not a lack of security in the NetSuite product, but a misconfiguration of the client that can lead to the leakage of sensitive data. Exposed information includes full addresses and mobile phone numbers of registered customers of e-commerce sites.

Cyber ​​security

The attack scenario detailed by AppOmni uses CRTs that use table-level access control with a “No Permission Required” access type that allows unauthenticated users to access data using NetSuite’s record and search APIs.

However, for this attack to be successful, there are a number of prerequisites, the main of which is the need for the attacker to know the name of the CRTs being used.

To reduce the risk, it is recommended that site administrators tighten access controls to CRTs, set privacy fields to “None” for public access, and consider temporarily taking affected sites offline to prevent data disclosure.

“The simplest solution from a security perspective might involve changing the access type in the entry type definition to ‘Require permission for user entries’ or ‘Use permission list,'” Costello said.

The disclosure came as Cymulate detailed a way to manipulate the credential validation process in Microsoft Entra ID (formerly Azure Active Directory) and bypass authentication in hybrid identity infrastructures, allowing attackers to gain elevated privileges within a tenant and establish security.

The attack, however, requires the adversary to have administrator access on the server hosting the End-to-end Authentication Agent (PTA), a module that allows users to log into both on-premises and cloud applications using Entra ID. The problem is rooted in Entra ID when syncing multiple on-premises domains to a single Azure tenant.

Cyber ​​security

“This issue occurs when end-to-end authentication agents (PTAs) incorrectly handle authentication requests for different local domains, leading to potential unauthorized access,” security researchers Ilan Kalendarov and Elad Beber said.

“This vulnerability effectively turns the PTA agent into a double agent, allowing an attacker to log in as any synced AD user without knowing their actual password; this could potentially grant access to the global admin user if such privileges were assigned.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.