Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

2026-07-28T01:23:40Z9e21844f7a7490164c166f940b8eee25edfc1cf2337571fd5b24bc31bc6a5211
ESAFENET CDGGeoServerSQL injectionSpring ActuatorSpring BootXSScredential exposureheapdump exposureinternet scanningsecret leakagethreat intelligenceweak passwords

What happened

SANS ISC reports internet scanning for exposed Java Spring Boot Actuator /actuator/heapdump endpoints, which can disclose heap memory containing API keys, database passwords, and other application secrets. It also notes scanning targeting ESAFENET CDG document management systems with weak logins and previously reported SQL injection and XSS issues. The feed includes additional observations about Geoserver activity and autonomous attacker disclosures, but provides no specific CVE identifiers.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
9e21844f7a7490164c166f940b8eee25edfc1cf2337571fd5b24bc31bc6a5211
Enrichment time
2026-07-28T01:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.