{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "eb4fa927f11cdafa2acd3d92ea908310f97ed6d59c1f70dc5accf114b92a5345",
    "authored_runtime_manifest_sha256": "73ab163b55e91cb1436dca2e94aec0ec005b97d826597d026f2b70c6b53855b5",
    "authored_verdict_sha256": "bd7976eaa367cba31562d730d99012dae6ca4dea6b2ef031b5241295cc2817fb",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "d6b54cf0-a582-442d-9b47-b66db7a5827a",
    "e484612e-9933-47af-88c9-9ab070cbec43",
    "19445c28-c62b-45a9-8219-db777b6cfa80"
  ],
  "attacker_controlled_input": "unauthenticated HTTP requests to /app: Tapestry direct-service path (service=direct/1/Home/ConfigEditor/...), ConfigEditor form field values (config keys/values), and the web-login card number (inputUsername) which becomes the Derby export query",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "POST /app?service=direct/1/Home/ConfigEditor/... (unauth config write of user-lookup.* / auth.web-login.card-id.*) -> POST /app service=direct/1/Home/$Form card login -> ExternalUserLookupDb CALL SYSCS_UTIL.SYSCS_EXPORT_QUERY_LOBS_TO_EXTFILE (file write as papercut) -> GET /app?service=page/Pwn3 (planted Tapestry page OGNL eval -> Runtime.exec) -> GET /pwn-proof.txt (remote command receipt)",
  "validated_surface": "api_remote"
}
