nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

Technology

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery
New research has uncovered continued risk from a known security weakness in Microsoft’s Entra ID, potentially enabling malicious actors to achieve account takeovers in susceptible software-as-a-service (SaaS) applications.
Identity security company Semperis, in an analysis of 104 SaaS applications, found nine of them to be vulnerable to Entra ID cross-tenant nOAuth abuse.
First disclosed by

Read original source here.

Products You May Like

Articles You May Like

Federal Judge Blocks Big Beautiful Bill From Defunding Planned Parenthood
Kelly Clarkson Postpones Las Vegas Residency Hours Before Opening Show
Grok Wrote Rape Fantasies About X User Before it Was Disabled
It’s Now Easier Than Ever to Watch Pokemon’s First Movie (For Free)
West LA volleyball team wins championship despite Palisades Fire – NBC Los Angeles