Reversing the Irreversible, again: Unlocking 'locked' Omnis Studio classes

preview_player
Показать описание
In this PoC video, SySS IT security expert Matthias Deeg demonstrates another attack concerning a violation of expected behavior regarding the rapid application software development tool Omnis Studio.

Omnis Studio supports an irreversible feature for locking classes within Omnis libraries. According to the Omnis Studio software, it should no longer be possible to delete, view, change, copy, rename, duplicate, or print a locked class.

However, during a security analysis of an application developed with Omnis Studio using this feature, Matthias Deeg found out that it is possible to unlock "locked" classes in Omnis libraries, and thus further analyze or modify them with the Omnis Studio browser.

This violates the expected behavior of an "irreversible operation".

You can find more details about the demonstrated security issue in our SySS security advisory SYSS-2023-006 [1]. The assigned CVE ID concerning the demonstrated security issue is CVE-2023-38334 [2].

[1] SySS Security Advisory SYSS-2023-006

[2] CVE-2023-38334

#security #vulnerability #poc
Рекомендации по теме
Комментарии
Автор

Für mich wäre jetzt spannend was da genau im Prozess gepatched wird.

slky