Learn
active
IDORacle: Runtime SQL-Sink Interception for IDOR/BOLA in Java Apps
- Engineer — Learn: Novel approach to enforcing object-level authorization at the MyBatis/JDBC boundary rather than the controller layer — worth reviewing if you own Java applications with IDOR exposure, but no tool is publicly released yet so no concrete action today.
- SOC/IR — Skip
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.