WAF – WAF Release – 2025-11-17

WAF – WAF Release – 2025-11-17

This week highlights enhancements to detection signatures improving coverage for vulnerabilities in DELMIA Apriso, linked to CVE-2025-6205.

Key Findings

This vulnerability allows unauthenticated attackers to gain privileged access to the application. The latest update provides enhanced detection logic for resilient protection against exploitation attempts.

Impact

  • DELMIA Apriso (CVE-2025-6205): Exploitation could allow an unauthenticated remote attacker to bypass security checks by sending specially crafted requests to the application’s message processor. This enables the creation of arbitrary employee accounts, which can be leveraged to modify system configurations and achieve full system compromise.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Rulesetec1e2aa190e64e7cb468e16dd256f4bc N/ADELMIA Apriso – Auth Bypass – CVE:CVE-2025-6205LogBlockThis is a new detection.
Cloudflare Managed Rulesetfae6fa37ae9249d58628e54b1a3e521e N/APHP Wrapper Injection – BodyN/ADisabledRule metadata description refined. Detection unchanged.
Cloudflare Managed Ruleset9c02e585db34440da620eb668f76bd74 N/APHP Wrapper Injection – URIN/ADisabledRule metadata description refined. Detection unchanged.

Source: Cloudflare



Latest Posts

Pass It On
Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply