CVE-2022-21587
KEV ransomware PoC largeUnauthenticated Arbitrary File Upload in Oracle E-Business Suite
CISA: Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite versions 12.2.3 through 12.2.11 contain a critical, unauthenticated arbitrary file upload flaw (CWE-306, missing authentication) in the Upload component of the Web Applications Desktop Integrator. Because exploitation requires no credentials and no user interaction, any attacker with HTTP network access to the affected component can trigger the flaw remotely and achieve takeover of Oracle Web Applications Desktop Integrator, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Organizations running any affected E-Business Suite 12.2 release are exposed, particularly where EBS interfaces are reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-02 with known ransomware use, EPSS assigns a 98.3% probability of exploitation within 30 days, and exploitation attempts were observed after a public proof-of-concept was released.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2022-21587 (October 2022 CPU or later) on all E-Business Suite 12.2.3-12.2.11 systems, per CISA's required action. Until patched, restrict internet access to EBS, especially the Web Applications Desktop Integrator upload endpoints, and review logs and uploaded-file locations for signs of exploitation. Prioritize remediation given confirmed active exploitation and ransomware use.
| Oracle E-Business Suite (Web Applications Desktop Integrator, Upload component) | 12.2.3 through 12.2.11 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected
- Oracle E-Business Suite
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- oracle
- Products
- e-business suite
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H