Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Halo ITSM Vulnerability Exposed Organizations to Remote Hacking

An unauthenticated SQL injection vulnerability in Halo ITSM could have been exploited to read, modify, or insert data.

UK-based Halo recently patched a potentially serious vulnerability in its IT service management (ITSM) software, attack surface management firm Assetnote reported on Wednesday.

According to Assetnote, HaloITSM is affected by an SQL injection vulnerability that could be exploited by an unauthenticated attacker. Roughly 1,000 cloud deployments may have been vulnerable to remote attacks, in addition to on-premises deployments exposed to network attackers. 

A threat actor could exploit the vulnerability to read, modify, or insert data into the ITSM software, explained Assetnote, a Searchlight Cyber company. 

“As an IT Support Management tool, Halo is often integrated with various internal and external systems and cloud providers, as well as containing sensitive information such as configuration files and credentials,” said Shubham Shah, SVP of Engineering and Research at Searchlight. 

Shah added, “This means that an attacker could have used this vulnerability to compromise any of the integrated systems, obtain sensitive data stored on the system, or even add themselves as an administrator and take over the instance.”

The vendor has patched the vulnerability with the release of versions 2.174.94, 2.184.23 (candidate), and 2.186.2 (beta), and on-premises instances should be updated as soon as possible.

Advertisement. Scroll to continue reading.

Assetnote pointed out that while this particular vulnerability has been patched, its analysis indicates that the Halo product has a large attack surface, being exposed particularly to post-authentication attacks. 

The security firm has made available technical details for the SQL injection vulnerability found in HaloITSM. 

Related: Details Emerge on CVE Controversy Around Exploited CrushFTP Vulnerability

Related: Google Released Second Fix for Quick Share Flaws After Patch Bypass

Related: Critical Vulnerability Found in Canon Printer Drivers

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.