AUTO-UPDATED

Exploiting vulnerabilities in Johnson and Johnson web apps

Security researcher reports reveal that Johnson & Johnson web applications contained critical vulnerabilities that exposed student data and internal audit records across twenty different corporate entities.

Key Points

  • A campus recruiting portal vulnerability exposed personal details and interview notes for nearly 1,000 students due to improper API authentication.
  • An internal Audit Tracking Management System (ATMS) allowed unauthorized administrative access, potentially exposing confidential meeting minutes and transcripts.
  • Both systems relied on insecure client-side authentication logic that failed to validate Microsoft SSO tokens, allowing researchers to bypass login requirements.
  • The researcher reported the flaws in October 2025, but the ATMS vulnerability remained unpatched until April 2026 following media intervention.
  • The ATMS platform served as a centralized hub for sensitive data across twenty J&J subsidiaries, including Ethicon, Janssen, and Abiomed.

Why it Matters

These security lapses highlight the significant risks associated with relying on client-side code for authentication in enterprise web applications. The delay in addressing the audit system vulnerability underscores the critical need for robust internal reporting processes to prevent potential data breaches.
Eaton-works.com Published by Eaton
Read original