Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

ConnectWise screenconnectRotate code signing certificate for security risk

TFI Lodestar and Coventry University announce collaboration to celebrate Phil Watton

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud
Identity

Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

userBy userJune 10, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 10, 2025Ravi LakshmananVulnerability / SaaS Security

Salesforce Industry Cloud

Cybersecurity researchers have discovered over 20 configuration-related risks affecting Salesforce Industry Cloud (aka Salesforce Industries), exposing sensitive data to fraudulent internal and external stakeholders.

The weaknesses affect a variety of components such as flexcards, data mappers, integration procedures (IPROCS), data packs, Omniout, and Omniscript retention sessions.

“Low code platforms such as Salesforce Industry Cloud make building applications easier, but the convenience costs when security is not prioritized,” said Appomni’s chief of SaaS Security Research in a statement shared with Hacker News.

These misconceptions allow unadapted access to sensitive data about employees and customers to cybercriminals and unauthorized encrypted sensitive data, allowing session data detailing how users interact with clouds in the Salesforce industry, Salesforce and other corporate systems, and how business logic.

Cybersecurity

Following responsible disclosure, Salesforce addressed three shortcomings and issued two more configuration guidance. The remaining 16 misconceptions are left to the client to fix them themselves.

Vulnerabilities assigned to CVE Identifiers are listed below –

CVE-2025-43697 (CVSS score: N/A) – If “Field Level Security” is not enabled for “Extract” and “Turbo Extract Data Mapper, the “View Encrypted Data” permission check is not enforced. The SOQL data source bypasses field-level security when retrieving data from the Salesforce object CVE-2025-43699 (CVSS score: 5.3). FlexCard does not force fields of Omniulcard object CVE-2025-43700 (CVSS score: 7.5) that do not use Omniulcard object CVE-2025-43700 (CVSS score: 7.5). Returns plain text value for data using classic encryption CVE-2025-43701 (CVSS score: 7.5) – FlexCard allows guest users to access the values ​​of custom settings

Simply put, attackers can weaponize these issues, bypassing security controls and extracting sensitive customer or employee information.

According to Appomni, CVE-2025-43967 and CVE-2025-43698 are being addressed through a new security setting called “endforcedMflsandDataEncryption,” in which only users who say “only customers are “enforced” must be enabled to secure only customers to ensure that only customers have “views” values ​​of plains in the fields returned to the Data Mapper.

“For organizations that are subject to compliance delegation such as HIPAA, GDPR, SOX, PCI-DSS, and other organizations, these gaps can represent actual regulations exposure,” the company said. “And since it’s the customer’s responsibility to safely configure these settings, one missed setting can be non-existent in the vendor’s accountability and could lead to thousands of records violations.”

When it reached the comment, a Salesforce spokesperson told Hacker News that the majority of the issues were “derived from customer configuration issues” and that they were not vulnerabilities inherent in the application.

“All issues identified in this study have been resolved, patches are now available to customers, and official documentation has been updated to reflect the full configuration capabilities,” the company said. “As a result of these issues, no evidence of exploitation in the customer environment has been observed.”

This disclosure is that security researcher Tobia Righi, who uses the handle Mastersplinter, has disclosed a Salesforce Object Language (SOQL) injection vulnerability that could be exploited to access sensitive user data.

Cybersecurity

Zero-day vulnerabilities (no CVE) exist in the default aura controller that exists in all Salesforce deployments. This is the result of the user-controlled “contentdocumentid” parameter.

The successful exploitation of the flaws could allow the attacker to insert additional queries via parameters, allowing the database to be extracted. Exploits can be further enhanced by passing a list of IDSs correlated to unpublished ContentDocument objects to gather information about uploaded documents.

According to Righi, the ID can be generated by an exposable brute force script that can generate possible previous or next Salesforce IDs based on a valid input ID. This is possible in turn by the fact that Salesforce ID does not actually provide security perimeters and is actually somewhat predictable.

“As mentioned in the study, after receiving the report, our security team quickly investigated and resolved the issue. We have not observed any evidence of exploitation in the customer environment,” a Salesforce spokesperson said. “We are grateful for Tobia’s efforts to responsibly disclose this issue to Salesforce, and continue to encourage the security research community to report potential issues through established channels.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGoogle deploys Android 16 to pixel phones and announces proposals for AI-driven editing for Google Photos
Next Article Adobe releases patches, fixes 254 vulnerabilities, closes high-strength security gaps
user
  • Website

Related Posts

ConnectWise screenconnectRotate code signing certificate for security risk

June 12, 2025

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

June 12, 2025

Former Black Busta members use Microsoft team and Python scripts in the 2025 attack

June 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

ConnectWise screenconnectRotate code signing certificate for security risk

TFI Lodestar and Coventry University announce collaboration to celebrate Phil Watton

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

Family File Suit Challenges Arkansas Law Requiring 10 Commandments to be posted in classrooms

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

What is the most popular casino in the US?

Top 10 Startup and Tech Funding News – June 11, 2025

Huawei launches Pura 80 series and challenges Apple in China’s premium phone market

Israeli AI AI Data Security Startup Cyera raises $540 million and doubles its valuation to $600 million in seven months

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.