Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
2026-07-27T13:23:40Z•3de8f3400ccac63ca8558fbab86f176042b90f58a03384212550452ae09e5f69
ActuatorESAFENET CDGGeoServerSQL injectionSpring BootXSScredential exposuredefault passwordsheapdumpinformation disclosureinternet scanningsecret leakageweak credentials
What happened
SANS Internet Storm Center reports widespread scanning for the exposed Spring Boot /actuator/heapdump endpoint, which can disclose Java heap memory containing API keys, database passwords, and other application secrets. The feed also notes scanning targeting ESAFENET CDG systems with weak logins and known SQL injection/XSS/default-password issues, plus observed activity involving GeoServer. The primary risk is unauthenticated information disclosure and subsequent credential abuse; no specific CVE is identified in the provided content.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3de8f3400ccac63ca8558fbab86f176042b90f58a03384212550452ae09e5f69
- Enrichment time
- 2026-07-27T13:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.