Imperva SecureSphere WAF, a security tool for applications , has a security vulnerability in some versions that allows attackers to bypass rules when inspecting POST data.
See also: Cisco Unity Connection: Critical vulnerability grants root privileges

If malicious content is injected by bypassing the WAF, attackers could potentially exploit any security vulnerabilities in the protected web applications that the WAF should protect, thereby threatening the security of those applications.
A critical vulnerability (CVE-2023-50969) exists in versions of Imperva SecureSphere WAF that do not have the update listed in the “Fixed Version(s)” section, allowing attackers to bypass WAF rules designed to inspect POST data, which could potentially allow the exploitation of vulnerabilities in protected applications that the WAF should normally block.
The attacker does not need to be authorized and can remotely exploit the vulnerability, while it is rated as critical due to the high severity of the security control bypass.
The malicious code, which exploits a PHP webshell called clam.php, creates a form that allows users to submit arbitrary commands via a text field.
When submitting the form, `system` is used to execute the submitted command on the server, creating a security risk because it allows attackers to remotely execute arbitrary code on the server, risking system compromise.
See also: Vulnerability in glibc allows root access on Linux distributions
The lack of proper data validation and security in the code allows malicious code to be injected through user input, which an attacker could use to upload malicious files, steal sensitive data, or take down the website.

There is a security vulnerability where a system rule can be executed via a POST request with a specific parameter, where WAF rules typically block such attempts (e.g., reading password files).
By using the Content-Encoding header, someone can bypass the rules by tricking Imperva WAF into misinterpreting the data and allowing the malicious command to be executed.
A specific rule weakness in Imperva WAF allows attackers to bypass security by sending a formatted HTTP request with a double Content-Encoding header (“No Kill No Beep Beep” and “deflate”) followed by a parameter that is discarded before the actual malicious data.
According to Hoya Haxa, a security vulnerability was reported in Imperva on November 10, 2023, while an update to address this vulnerability was released through Imperva's ADC rules on February 26, 2024, while details about the vulnerability and its remediation process were publicly disclosed via a blog post on March 27, 2024.
See also: Microsoft SharePoint: Critical vulnerability used for attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cyberattacks can have a significant impact on users’ daily lives, as many of our activities depend on digital technology. From our personal communication and banking, to our access to healthcare and education, cyberattacks can cause serious disruption. When it comes to security, cyberattacks are a growing threat. From stealing personal data and violating privacy, to carrying out digital attacks that can cause physical damage, cyberattacks pose a serious threat to user security. In addition, cyberattacks can have significant economic consequences. Data loss, service interruptions and the need for recovery can cost businesses millions. This can lead to higher prices for consumers and job losses.
Source: gbhackers
