Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

2026-07-27T13:23:40Z3de8f3400ccac63ca8558fbab86f176042b90f58a03384212550452ae09e5f69
ActuatorESAFENET CDGGeoServerSQL injectionSpring BootXSScredential exposuredefault passwordsheapdumpinformation disclosureinternet scanningsecret leakageweak credentials

What happened

SANS Internet Storm Center reports widespread scanning for the exposed Spring Boot /actuator/heapdump endpoint, which can disclose Java heap memory containing API keys, database passwords, and other application secrets. The feed also notes scanning targeting ESAFENET CDG systems with weak logins and known SQL injection/XSS/default-password issues, plus observed activity involving GeoServer. The primary risk is unauthenticated information disclosure and subsequent credential abuse; no specific CVE is identified in the provided content.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3de8f3400ccac63ca8558fbab86f176042b90f58a03384212550452ae09e5f69
Enrichment time
2026-07-27T13:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.