Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
ID: bbbaa008-804a-587d-ad09-2ad5744ae91a
STIX ID: report--bbbaa008-804a-587d-ad09-2ad5744ae91a
Feed Name: SANS ISC Diary
Threat Score
The report documents observed requests targeting a Spring Boot actuator heapdump endpoint at `/admin-api/actuator/heapdump`, using Basic auth with the default credentials `admin:admin`. Because Java heapdumps can contain application secrets (API keys, database credentials), exposure of this management endpoint or use of weak/default passwords can lead to sensitive data leakage; the author recommends restricting access via Spring Security and proper configuration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
