# Exploiting vulnerabilities in Johnson & Johnson web apps

DevFeed: [Exploiting vulnerabilities in Johnson & Johnson web apps](<https://devfeed.tech/articles/exploiting-vulnerabilities-in-johnson-johnson-web-apps-32621.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/06/24/jnj-webapp-hacks/>)

Author: Eaton

Published: 2026-06-24T16:11:49Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Web](<https://devfeed.tech/topics/web.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [data](<https://devfeed.tech/topics/data.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apis](<https://devfeed.tech/tags/apis.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [data](<https://devfeed.tech/tags/data.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

## AI overview

The article reports vulnerabilities in two Johnson & Johnson web applications. A campus recruiting application exposed student information because its APIs used a hardcoded AWS API key instead of the Microsoft SSO token. The article also reports a vulnerability in the Audit Tracking Management System involving confidential internal audit data.

## Source excerpt

Campus Recruiting vulnerability exposed student information, and Audit Tracking Management System vulnerability exposed confidential internal audit data.