Understanding OWASP API 06:2023 Unrestricted Access to Sensitive Business Flows
In July 2023, a serious breach involving Ivanti’s EPMM surfaced due to the CVE-2023-35078 zero-day vulnerability. Attackers exploited this flaw, gaining unauthorized API access, manipulating server functions, and potentially exfiltrating…