Vulnerabilities & PatchesEmerging1 src
Issue 161: Vulnerability in Wipro Holmes Orchestrator, report into vulnerabilities in FinTech and banking apps
This week, we have details of a vulnerability in the AI platform Wipro Holmes Orchestrator, allowing the download of arbitrary files via path manipulation.
There’s also a new report from researcher Alissa Knight on vulnerabilities in banking, cryptocurrency exchange, and FinTech APIs; an article on the impact of a shift-left approach for API security; and 31 tips for improving API security; and an upcoming webinar on automating API protection.
Vulnerability: Arbitrary file download in Wipro Holmes Orchestrator
This week saw the disclosure of a vulnerability hat affected the AI platform Wipro Holmes Orchestrator, as detailed in this disclosure and tracked as CVE-2021-38146 .
The vulnerability was discovered by researcher Rizal Muhammed, who provided a sample Python script to demonstrate the exploit.