# Lessons in Securing Mobility Site Management APIs

DevFeed: [Lessons in Securing Mobility Site Management APIs](<https://devfeed.tech/articles/lessons-in-securing-mobility-site-management-apis-32609.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/05/16/jnj-mobility-hack/>)

Author: Eaton

Published: 2024-05-16T04:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Mobile](<https://devfeed.tech/topics/mobile.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [network](<https://devfeed.tech/tags/network.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

This article examines vulnerabilities in the PHP APIs behind Johnson & Johnson's Mobility Service Portal. Researchers reported that the vulnerabilities allowed access to details about employee corporate devices, and Johnson & Johnson remediated the issue after receiving the report.

## Source excerpt

(ASPEN) Mobile device management (MDM) systems are essential for large enterprises to track devices accessing the corporate network and ensure security. Read how a vulnerability on Johnson & Johnson's Mobility Service Portal made it possible to access employee corporate devices.