CISA Warns of Actively Exploited Critical Oracle Fusion Middleware Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-35587 | Unauthenticated RCE in Oracle Access Manager (OpenSSO Agent) CVE-2021-35587 is a critical (CVSS 9.8) missing-authentication flaw (CWE-306) in the OpenSSO Agent component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker with network access can send crafted HTTP requests to the affected component and, because the endpoint requires no authentication, achieve takeover of Oracle Access Manager — effectively pre-authentication remote code execution with high impact on confidentiality, integrity, and availability. Organizations running Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0, or 12.2.1.4.0 are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-11-28, and security press reported more than 150 internet-exposed Oracle Access Management systems. EPSS assigns a 96.3% probability of exploitation within 30 days, although no public proof-of-concept code is known. Do: Apply Oracle's update for CVE-2021-35587 per vendor instructions (delivered via the Oracle Critical Patch Update covering this flaw) to bring Access Manager 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 to a fixed release; this is the required action in CISA's KEV entry. Until patched, restrict HTTP access to OpenSSO Agent/Access Manager endpoints at the perimeter and review access logs for signs of unauthenticated exploitation. | 9.8 | 96% | KEV |
| niche≈150+ internet-exposed Oracle Access Manager systems identified by public scans | |
| CVE-2022-4135 | Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera) CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known. Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists. | 9.6 | 32% | KEV PoC |
| mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown) |
Full article269 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 29, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Oracle Fusion Middleware to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2021-35587, carries a CVSS score of 9.8 and impacts Oracle Access Manager (OAM) versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0.
Successful exploitation of the remote command execution bug could enable an unauthenticated attacker with network access to completely compromise and take over Access Manager instances.
"It may give the attacker access to OAM server, to create any user with any privileges, or just get code execution in the victim's server," Vietnamese security researcher Nguyen Jang (Janggggg), who reported the bug alongside peterjson, noted earlier this March.
The issue was addressed by Oracle as part of its Critical Patch Update in January 2022.
Additional details regarding the nature of the attacks and the scale of the exploitation efforts are immediately unclear. Data gathered by threat intelligence firm GreyNoise shows that attempts to weaponize the flaw have been ongoing and originate from the U.S., China, Germany, Singapore, and Canada.
Also added by CISA to the KEV catalog is the recently patched heap buffer overflow flaw in the Google Chrome web browser (CVE-2022-4135) that the internet giant acknowledged as having been abused in the wild.
Federal agencies are required to apply the vendor patches by December 19, 2022, to secure their networks against potential threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/11/cisa-warns-of-actively-exploited.html