Flaws in SmartVista Payment Platform Expose Sensitive Data

Unpatched SQL injection vulnerabilities found by Rapid7 researchers in the SmartVista e-payments suite from Switzerland-based BPC Banking Technologies can expose sensitive information.
The SmartVista platform is used by major organizations around the world for online banking, e-commerce, ATM and card management, and fraud prevention. The core components of the SmartVista suite are the Front-End and Back-Office systems.
Researchers at Rapid7 discovered that the SmartVista Front-End, specifically version 2.2.10 revision 287921, is affected by two SQL injection vulnerabilities.
移动办公的员工不应带来安全风险,组织可以在内网和网关部署网络安全及应用监管相关的系统,现在以及不远的将来,移动办公使员工和工作终端越来越多地逃离这种监管和保护,当然会带来更多的安全风险。
According to the security firm, an attacker who has access to the SmartVista Front-End interface can exploit the flaws to obtain data stored in the backend database.
The “Transactions” page in the “Customer Service” section of SmartVista Front-End allows users to view transaction details associated with a specified card or account. However, the fields where the card and account number are entered fail to sanitize user-supplied input.
This allows a malicious actor to use specially crafted queries to get the application to display data from the backend database, including usernames, passwords, card numbers, and other transaction details.
Rapid7 researchers demonstrated that entering a Boolean search term such as ‘ or ‘1’=’1, in the “Account Number” field resulted in all transactions being displayed. While there is a 5 second delay when a similar Boolean search term is entered into the “Card Number” field, a time-based SQL injection attack is still possible.
Rapid7 reported its findings to BPC on May 10, but a patch has yet to be released. CERT/CC and SwissCERT have also tried contacting the vendor, but without any success. The security firm gives vendors at least 60 days before publicly disclosing vulnerabilities found in their products.
SecurityWeek has reached out to BPC for comment and will update this article if the company responds.

“Users should contact BPC support for more details. In the meantime, access to the management interface of SmartVista should be as limited as possible, and audits of successful and failed logins should be performed regularly. A web application firewall (WAF) can help mitigate, or at least complicate, exploitation that relies on common SQL injection techniques,” Rapid7 advised users.
网络安全法宣传片 002 国家网络安全的现状与重要性概述
Related: Millions of Endpoints Exposed via RDP
Related: Millions of Devices Remain Exposed via SMB, Telnet Ports
Related: Rapid7 Appointed CVE Numbering Authority
移动计算设备的盛行让公司系统和数据的接入无处不在,传统的边界安全已经模糊;员工自己的移动设备使公司信息的访问、处理和存储也可以随时随地完成。

猜您喜欢

湘潭多部门问诊人员密集场所 筑防火墙
中国人到海外如何与当地文化、当地人民进行安全地沟通和融合:
CyberSecurity Law Introduction 网络安全法宣传视频系列
抢次新股龙头宝座 这只股票集多重概念于一身
MADDIM GREENROWBOOKS
信息安全知识试题