Conflicts between URL mapping and URL based access control., (Mon, Nov 24th)

SANS Internet Storm Center, InfoCON: green 2025-11-24

Summary:

We continue to encounter high-profile vulnerabilities related to the use of URL mapping (or "aliases") with URL-based access control. Last week, we wrote about the Oracle Identity Manager vulnerability. I noticed some scans for an older vulnerability with similar roots today:

Link:

https://isc.sans.edu/diary/rss/32518

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

11/24/2025, 14:36

Date published:

11/24/2025, 11:54