Web Application Penetration Test

Cover image for Web Application Penetration Test
Security & Compliance

Broken object-level authorisation vulnerability identified in the REST API, allowing one authenticated user to access an…

Web Application Penetration Test

Technology / SaaS · North America

Session token entropy was insufficient — tokens were predictable under certain conditions, enabling session hijacking without credentials.All 12 findings were remediated before the client's enterprise customer security review, enabling a $1.2M contract to proceed on schedule.
May 15, 20262 min read

At a glance

Executive Summary

Project Details

Industry

Technology / SaaS

Region

North America

Services Provided

  • Web Application Penetration Testing
  • API Security Assessment
  • OWASP Top 10 Evaluation
  • Authentication Testing
  • Remediation Guidance

Key Takeaways

  • Session token entropy was insufficient — tokens were predictable under certain conditions, enabling session hijacking without credentials.
  • All 12 findings were remediated before the client's enterprise customer security review, enabling a $1.2M contract to proceed on schedule.

Overview

A SaaS platform provider required a web application penetration test before onboarding a new enterprise customer who mandated third-party security validation as a contract condition. Blue Orca conducted a grey-box assessment of the platform's web application and REST API, simulating an authenticated attacker with standard user access. The engagement covered the OWASP Top 10 and included specific focus on multi-tenant data isolation and API authorisation logic.

Key outcomes

$1.2M

Client's enterprise customer accepted the penetration test report…

$1.2M

All 12 findings were remediated before the client's enterprise custom…

$1.2M

. A SaaS platform provider required a web application penetration tes…

Deep dive

Case Narrative

Challenges

  • The application served multiple tenants from a shared infrastructure — data isolation boundaries had to be tested carefully without triggering unintended data exposure.
  • The REST API had no formal documentation; endpoint enumeration and parameter fuzzing were required to map the attack surface.
  • Enterprise contract timelines meant all findings had to be communicated, remediated, and retested within a four-week window.
  • The development team had limited prior exposure to security testing, requiring clear and actionable remediation guidance rather than generic vulnerability references.

Our Approach

  • Application Mapping and Authentication ReviewBlue Orca mapped all application endpoints, authentication flows, and session management mechanisms. Cookie attributes, token entropy, and logout behaviour were assessed against current best-practice standards. Two issues were identified at this stage: insufficient session token entropy and a missing Secure cookie flag on authentication cookies.
  • Authorisation and Multi-Tenant Isolation TestingUsing two test accounts in separate tenant environments, Blue Orca tested horizontal and vertical privilege escalation across all identified API endpoints. A broken object-level authorisation (BOLA) vulnerability was confirmed that allowed Tenant A's authenticated session to retrieve Tenant B's account and billing records by manipulating a numeric ID parameter in API requests.
  • Input Validation and Injection TestingAll user-controlled inputs were tested for injection vulnerabilities including SQL injection, cross-site scripting, and server-side request forgery. One stored XSS vulnerability was found in a user profile field rendered in the admin dashboard. Injection points were tested against parameterised query validation controls with no SQL injection findings recorded.
  • Developer Briefing and Remediation SupportBlue Orca delivered a developer-focused remediation session alongside the written report, walking the engineering team through each finding with code-level guidance. The BOLA finding received detailed remediation logic covering object ownership validation in API middleware. A retest confirmed all 12 findings resolved within the four-week window.

Results

  • Broken object-level authorisation vulnerability identified and remediated — no cross-tenant data exposure risk remains.
  • Session management hardenedtoken entropy increased and all cookie security attributes enforced.
  • All 12 findings remediated and verified in retest within the four-week enterprise contract window.
  • Client's enterprise customer accepted the penetration test report and the $1.2M contract was executed on schedule.

Why Blue Orca Solutions?

Blue Orca delivered a technically rigorous web application assessment with developer-friendly remediation guidance, enabling a SaaS provider to satisfy enterprise security requirements and close a material contract without delay.

Plan your next engagement

Ready to achieve similar outcomes?

Talk to Blue Orca about your priorities. We’ll map a delivery approach aligned to your goals, team capacity, and risk profile.

Continue reading

Related Case Studies