Transitioning a sensitive on-premises GlassFish infrastructure from implicit network trust to a resilient, defense-in-depth security model using OWASP assessment methodologies.
A prominent public sector organization managing critical internal infrastructure and handling highly sensitive state information.
Operating within an entirely isolated on-premises intranet, the client relied strictly on perimeter security, enterprise firewalls, and virtual local area network (VLAN) segmentation. This created a fragile "hard shell, soft center" security architecture where application-layer patching and host-level hardening were neglected under the false assumption that an internal network is inherently safe.
We simulated an internal adversary leveraging the OWASP Testing Methodology to evaluate a sensitive, unpatched on-premises infrastructure deployment.
Based in South Africa, the client is a prominent government sector organization managing critical internal infrastructure and handling highly sensitive data. To protect their assets, they operate entirely within an isolated intranet environment, shielded from public internet exposure by enterprise-grade firewalls and strict access controls.
Relying entirely on perimeter walls created deep security vulnerabilities across the internal application layer:
QBurst’s specialized cybersecurity division initiated a comprehensive, controlled white-hat pentesting engagement. Mimicking a malicious insider or a lateral-moving malware strain, we attached a standard endpoint directly to a trusted network node to systematically audit the hidden application layer.
| OWASP Category | Finding Count | Severity | Architectural Risk & Business Impact |
| A01:2021 – Broken Access Control | 3 | Critical | Enables unauthenticated path traversal to access arbitrary system files, unauthorized directory access, and administrative panel exposure. |
| A06:2021 – Vulnerable and Outdated Components | 1 | High | Leaves system exposed to publicly documented exploits and unsupported End-of-Life (EOL) middleware/OS dependencies. |
| A02:2021 – Cryptographic Failures | 2 | Medium | Exposes unencrypted service credentials in configuration files and exposes network traffic via outdated SSL/TLS cipher suites. |
| A04:2021 – Insecure Design | 2 | Medium | Absence of rate-limiting controls and resource consumption bounds leaves host susceptible to brute-force attacks and internal Denial of Service (DoS). |
| A05:2021 – Security Misconfiguration | 10 | Medium | Facilitates system fingerprinting, arbitrary code execution via default deployments, lingering legacy artifacts, unencrypted admin traffic, and missing HTTP security headers. |
| A07:2021 – Identification and Authentication Failures | 2 | Medium | Increases susceptibility to automated password guessing, session hijacking, and unauthorized administrative takeover due to weak policies and excessive timeouts. |
| A09:2021 – Security Logging and Monitoring Failures | 2 | Info | Prevents real-time detection of active exploits and impairs forensic audit capabilities during security incidents. |
This engagement was explicitly structured as an analytical risk-mapping assessment to generate mitigation blueprints. Final validation and retesting of engineering patches were excluded from the project scope.

Client Profile
Challenges
Solution
Intranet Vulnerability Registry
Key Features and Technical Highlights
Impact