Blog | G5 Cyber Security

Critical Java bug found in PayPal servers

Security researcher Michael Artsploit Stepankin discovered a critical security flaw on one of PayPals business websites, in the interface for PayPal Manager. He could execute arbitrary commands on manager.paypal.com web servers and that he could install a connection to his own server. The PayPal bug is now fixed, though PayPal Engineering says a lack of media attention contributed in part to it having been overlooked for so long. Two researchers, within days of each other, discovered the same, critical hole that happens when the data packets are deserialized.”]

Source: https://nakedsecurity.sophos.com/2016/01/27/critical-java-bug-found-in-paypal-servers/

Exit mobile version