S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2021-38147 Scanner

CVE-2021-38147 Scanner - Information Disclosure vulnerability in Wipro Holmes Orchestrator

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-38147
7.5
CVSS

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Wipro Holmes Orchestrator is a widely used software solution for orchestrating various business processes within an organization. It is employed by enterprises for automating repetitive tasks, generating detailed reports, and improving operational efficiency. The software allows for integration with various IT systems and tools, making it a versatile option for different industries. Wipro Holmes Orchestrator is primarily utilized by IT and operations departments who require streamlined workflow automation coupled with data analytics. It features a user-friendly interface that enables easy customization and process automation. Due to its comprehensive functionality, it is crucial to ensure its security to protect sensitive organizational data.

This vulnerability relates to the exposure of sensitive information within the Wipro Holmes Orchestrator. Due to improper authorization checks on certain API endpoints, remote attackers can exploit this flaw to download sensitive reports. The ability to access these files without authentication poses a significant risk as it can lead to unauthorized disclosure of confidential business information. Exploitation of this vulnerability requires minimal interaction, thus making it a high-severity issue. It emphasizes the necessity of robust authentication mechanisms to safeguard sensitive data. Addressing this issue can prevent potential data breaches and maintain client trust in the software product.

Wipro Holmes Orchestrator version 20.4.1 contains an information disclosure vulnerability at several API endpoints. These endpoints, such as processexecution/DownloadExcelFile, allow remote attackers to download Excel files containing sensitive report data without requiring authentication. The vulnerability lies in the absence of proper access control measures, making it possible for attackers to access files like Domain_Credential_Report_Excel, User_Report_Excel, Process_Report_Excel, Infrastructure_Report_Excel, and Resolver_Report_Excel. These open endpoints provide opportunities for data exfiltration by malicious entities. Adequate measures for authentication and authorization checks are vital to addressing potential security threats.

If exploited, this vulnerability can have severe repercussions including loss of sensitive data, financial loss, and reputational damage. Attackers could misuse the disclosed information for fraudulent activities or to gain unauthorized access to company resources. Depending on the nature of the exposed reports, this data compromise could impact internal operations and client relationships. Moreover, the financial implications of a data breach stemming from this flaw could be substantial, resulting in legal penalties and loss of customer trust. Corrective actions are critical to mitigate these possible effects and secure the organization’s data assets.

REFERENCES

Solution Advice
  • Upgrade to Wipro Holmes Orchestrator version 21.4.0 or later, where the vulnerability is fixed.
  • Implement strict authentication and authorization checks on all API endpoints.
  • Regularly audit API endpoints to identify and prevent unauthorized access.
  • Deploy web application firewalls to monitor and block malicious requests.
  • Conduct periodic security assessments and penetration testing to detect potential vulnerabilities early.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-38147 Scanner - Information Disclosure vulnerability in Wipro Holmes Orchestrator S4E