ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Oracle Fusion Middleware Vulnerability Actively Exploited in the Wild: CISA

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-35587CVE-2022-4135

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35587
Unauthenticated RCE in Oracle Access Manager (OpenSSO Agent)

CVE-2021-35587 is a critical (CVSS 9.8) missing-authentication flaw (CWE-306) in the OpenSSO Agent component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker with network access can send crafted HTTP requests to the affected component and, because the endpoint requires no authentication, achieve takeover of Oracle Access Manager — effectively pre-authentication remote code execution with high impact on confidentiality, integrity, and availability. Organizations running Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0, or 12.2.1.4.0 are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-11-28, and security press reported more than 150 internet-exposed Oracle Access Management systems. EPSS assigns a 96.3% probability of exploitation within 30 days, although no public proof-of-concept code is known.

Do: Apply Oracle's update for CVE-2021-35587 per vendor instructions (delivered via the Oracle Critical Patch Update covering this flaw) to bring Access Manager 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 to a fixed release; this is the required action in CISA's KEV entry. Until patched, restrict HTTP access to OpenSSO Agent/Access Manager endpoints at the perimeter and review access logs for signs of unauthenticated exploitation.

9.896% KEV
  • Oracle Access Manager (component: OpenSSO Agent) of Oracle Fusion Middleware 11.1.2.3.0, 12.2.1.3.0, 12.2.1.4.0
niche≈150+ internet-exposed Oracle Access Manager systems identified by public scans
CVE-2022-4135
Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera)

CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists.

9.632% KEV PoC
  • Google Chromium GPU (GPU process component of the Chromium engine)
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown)
Full article410 words · extracted from infosecurity-magazine.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw affecting Oracle Fusion Middleware systems to its Known Exploited Vulnerabilities (KEV) Catalog on Monday.

The bug, which CISA confirmed has been exploited in the wild, allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager. Successful attacks targeting this vulnerability can consequently result in the program's takeover.

Because of these factors, the vulnerability (tracked CVE-2021-35587) has been assigned a CVSS 3.1 base score of 9.8.

"CISA has grown more proactive in adding vulnerabilities to the list when they pose a threat," commented Mike Parkin, senior technical engineer at Vulcan Cyber.

"That's especially apparent when the vulnerability is being actively exploited in the wild, as these appear to be. We can expect to see this happen more often as they take a more aggressive stance on dealing with threats to the organizations they protect."

Oracle addressed the flaw as part of its Critical Patch Update Advisory in January this year. The fact that CISA is now adding it to its KEV Catalog means that one or more systems had not been adequately updated within this time frame, enabling attackers to exploit the bug.

"Whenever stories like these break, they should be used by security teams as an opportunity to lobby for security budget and prioritization," said Jamie Boote, associate principal consultant at the Synopsys Software Integrity Group.

"When the government acknowledges that unpatched vulnerabilities that have been out for nearly a year are a problem, it can be [a] much-needed assist to struggling security teams."

In the same announcement, CISA also added to the KEV Catalog the heap buffer overflow flaw in the Chrome web browser (CVE-2022-4135) that Google confirmed had also been exploited in the wild and more recently patched.

"Browser exploits have gone down in recent years. However, their importance has only increased as the primary interface almost everyone has to everything they do on the internet," said John Bambenek, principal threat hunter at Netenrich.

"Anytime there is active exploitation, it only increases the importance to update machines quickly. My only real concern is that a three-week deadline gives attackers plenty of time to keep racking up wins in the meantime. This has to get much faster."

The news comes two months after secure cloud experts at Wiz discovered a separate vulnerability in Oracle Cloud Infrastructure (OCI) that would allow unauthorized access to the cloud storage volumes of all users.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/oracle-fusion-middleware-flaw/