CVE-2022-21587
Oracle E-Business Suite Unspecified Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 February 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.34% probability · 100th percentile
- CISA KEV
- Listed 2 February 2023 · due 23 February 2023 · used in ransomware campaigns
- Weakness
- CWE-306
- Affected
- oracle/e-business suite
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://www.oracle.com/security-alerts/cpuoct2022.html; https://nvd.nist.gov/vuln/detail/CVE-2022-21587
References
- http://packetstormsecurity.com/files/171208/Oracle-E-Business-Suite-EBS-Unauthenticated-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuoct2022.htmlPatch, Vendor Advisory
- http://packetstormsecurity.com/files/171208/Oracle-E-Business-Suite-EBS-Unauthenticated-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuoct2022.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21587US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.