Other Software and Data

Welcome to the community!  Please feel free to start a discussion in the discussion tab or join in a conversation.

Discussions

Members

Resources

Events

 View Only
  • 1.  Vulnerabilities found in Catchment360 application during ASLC observation.

    Posted 08-22-2017 09:44

    1. Session does not expire on closing the browser

    2. Application is vulnerable to HTML injection attack

    3. Dangerous HTTP methods are enabled on the server

    4. Sensitive data is accessible from cache

    5. Sensitive information revealed in HTTP response

    6. Application is vulnerable to stored Cross Site Scripting attack

    7. Application is vulnerable to CSRF attack

    8. Application accepts special characters as user inputs

    9. Auto-complete is enabled for sensitive fields

    10. Server Side input validations are not in place

    11. DOS using sql wildcards



  • 2.  RE: Vulnerabilities found in Catchment360 application during ASLC observation.

    Employee
    Posted 08-22-2017 13:11

    Hello Jawed,

    Welcome, and thanks for your questions. I did some research and it looks like Catchment 360 is a custom application built on top of Spectrum Spatial. I've contacted our internal services team who should be reaching out to you shortly to help resolve any issues. In the meantime, thanks for being a part of the community, and I look forward to future interactions!

    Patrick Collins

    Senior Product Manager

    Location Intelligence Module