wonderfully unique software solutions

Enterprise data security vendor Stormshield reports on critical cloud vulnerabilities

IT/OT security specialist Stormshield has reported a new cloud-marketplace critical vulnerability, outlined by the US NIST National Vulnerability Database as CVE-2023-49103.

According to Stormshield customer security lab researcher Pierre-Olivier Kaplan, CVE-2023-49103 affects ownCloud servers through its app graphapi 0.2.0-0.3.0.

“This vulnerability has a CVSS 3.1 score of 10, the highest possible. This flaw allows an attacker, remotely and without any authentication, to read a phpinfo file that contains many sensitive information about the local environment,” warned Kaplan.

This potentially included configuration details and user information. On containerised deployments, the situation is “even worse”, according to Kaplan, as it also includes ownCloud admin password, mail server credentials, database credentials, and licence key.

He added that network security offerings like its own are capable of detecting and blocking related exploits. Meanwhile, users should update ownCloud and graphapi.

The news follows Stormshield integration of Bitdefender URL filtering, on the back of an extended partnership with the latter vendor announced in April 2023.

Stormshield offers solutions for data security in the enterprise as well as network and endpoint security for organisations through the channel.

Stormshield Data Security Enterprise (SDS Enteprise) boasts abilities to cover off data security requirements even for very large global organisations with internal and external employees across hundreds of offices all working together.

Data exchanges of staffers across storage, mobile devices and more can be traced and kept safe, minimising risk from negligence or information leakage.

“The loss or theft of critical information can all have a major impact on the company. However, this objective becomes rather more problematic in the case of an organisation based in several countries and having different local partners,” according to this Stormshield case study.

Data security should cover not only employee workstations by external partners such as service providers, the vendor suggested, if there is to be “an effective and sovereign solution”.

( Photo by Christin Hume on Unsplash )

Recent Articles

Vyond bundles in further AI and branding capabilities for corporate creatives

Video creation platform vendor Vyond is expanding its offerings with new brand-management tools as well as further generative AI functionality responding to...

LastPass analyst warns of looming credentials crisis

Organisations should beware of an oncoming crisis in the secure management of user access, according to a cybersecurity specialist at password management...

Octopus Deploy follows Codefresh buy with 2024.1 Server

Continuous delivery (CD) pipeline platform vendor Octopus Deploy has acquired fellow development software specialist Codefresh and rolled out a new version of...

Top-25 cloud list runs gamut from Visma to Cloudflare, Wasabi to Azul

The Software Report market insights website has named 25 software companies as the top companies in cloud computing for 2024, offering specific...

TeamViewer partners Deloitte on digital visuals for warehouse logistics

Deloitte and TeamViewer have combined the latter's augmented reality (AR) based visual picking offering with SAP Extended Warehouse Management (EWM) for warehousing...

Related Stories

Leave A Reply

Please enter your comment!
Please enter your name here

Weirdware monthly - Get the latest news in your inbox