CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11357 | Unauthenticated Arbitrary File Upload/RCE in Progress Telerik UI for ASP.NET AJAX CVE-2017-11357 is an insecure direct object reference in the RadAsyncUpload control of Progress Telerik UI for ASP.NET AJAX: user input is not properly restricted, so an unauthenticated remote attacker can upload arbitrary files to attacker-chosen locations. Because an attacker can drop a malicious file such as an ASPX web shell and then trigger it, the flaw leads to arbitrary code execution on the affected web server (CVSS 3.1 9.8; CWE-434). Any ASP.NET web application running Telerik UI for ASP.NET AJAX before R2 2017 SP2 that exposes the upload handler to untrusted users is affected. A public proof of concept is available (Exploit-DB 43874), and exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-26 with known ransomware use, has an EPSS of 77.7% (100th percentile), and recent news reports tied Telerik exploitation to the breach of a U.S. federal agency, in line with NSA/ASD warnings about web shell deployments. Do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP2 or later per vendor instructions; if the control is embedded in a third-party application, obtain updated builds from that application's vendor. Audit web roots and upload directories for unexpected .aspx/.asp files and web shells, review IIS logs for suspicious requests to the Telerik upload handler, and restrict internet access to the RadAsyncUpload handler if immediate patching is not possible. Given confirmed ransomware use, prioritize internet-facing systems and treat any evidence of file uploads through the handler as potential compromise. | 9.8 | 78% | KEV ransomware PoC |
| largetens of thousands of internet-exposed ASP.NET applications using Telerik UI (likely more, since the component ships embedded in internal and third-party apps) | |
| CVE-2022-21587 | Unauthenticated Arbitrary File Upload in Oracle E-Business Suite Oracle E-Business Suite versions 12.2.3 through 12.2.11 contain a critical, unauthenticated arbitrary file upload flaw (CWE-306, missing authentication) in the Upload component of the Web Applications Desktop Integrator. Because exploitation requires no credentials and no user interaction, any attacker with HTTP network access to the affected component can trigger the flaw remotely and achieve takeover of Oracle Web Applications Desktop Integrator, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Organizations running any affected E-Business Suite 12.2 release are exposed, particularly where EBS interfaces are reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-02 with known ransomware use, EPSS assigns a 98.3% probability of exploitation within 30 days, and exploitation attempts were observed after a public proof-of-concept was released. Do: Apply the Oracle Critical Patch Update that addresses CVE-2022-21587 (October 2022 CPU or later) on all E-Business Suite 12.2.3-12.2.11 systems, per CISA's required action. Until patched, restrict internet access to EBS, especially the Web Applications Desktop Integrator upload endpoints, and review logs and uploaded-file locations for signs of exploitation. Prioritize remediation given confirmed active exploitation and ransomware use. | 9.8 | 98% | KEV ransomware PoC |
| largetens of thousands of E-Business Suite deployments worldwide, with thousands of internet-exposed instances (estimate) | |
| CVE-2023-22952 | Authenticated PHP Code Injection RCE in SugarCRM EmailTemplates CVE-2023-22952 is a remote code execution vulnerability in multiple SugarCRM products caused by missing input validation (CWE-20) that permits PHP code injection (CWE-94) through the EmailTemplates feature. An attacker with low-privilege (authenticated) access sends a crafted request to EmailTemplates that injects and executes arbitrary custom PHP code on the server. Successful exploitation yields full server-side code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), and the associated public proof-of-concept demonstrates shell upload, creating risk of follow-on activity such as ransomware. Organizations running affected SugarCRM releases prior to 12.0 Hotfix 91155 are exposed. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2023-02-02, EPSS assigns an 80.1% probability of exploitation within 30 days (100th percentile), and trade press reported active attacks. Do: Apply the vendor fix immediately per CISA's KEV required action — SugarCRM 12.0 Hotfix 91155 or a later patched release per vendor instructions. Audit EmailTemplates and the server filesystem for injected PHP code or uploaded webshells, and review web logs for crafted requests to EmailTemplates endpoints. Treat unpatched, internet-exposed SugarCRM instances as high priority, as ransomware use is listed as unknown and active exploitation is confirmed. | 8.8 | 80% | KEV PoC |
| moderate≈10k–100k users across thousands of independently deployed business instances (order-of-magnitude estimate) |
Full article261 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 03, 2023Vulnerability Management
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on February 2 added two security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.
The first of the two vulnerabilities is CVE-2022-21587 (CVSS score: 9.8), a critical issue impacting versions 12.2.3 to 12.2.11 of the Oracle Web Applications Desktop Integrator product.
"Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator," CISA said.
The issue was addressed by Oracle as part of its Critical Patch Update released in October 2022. Not much is known about the nature of the attacks exploiting the vulnerability, but the development follows the publication of a proof-of-concept (PoC) by cybersecurity firm Viettel on January 16, 2023.
The second security flaw to be added to the KEV catalog is CVE-2023-22952 (CVSS score: 8.8), which relates to a case of missing input validation in SugarCRM that could result in the injection of arbitrary PHP code. The bug has been fixed in SugarCRM versions 11.0.5 and 12.0.2.
The development comes a week after CISA also added CVE-2017-11357 (CVSS score: 9.8), a severe security vulnerability impacting Telerik UI that could facilitate arbitrary file uploads or remote code execution.
In light of active exploitation attempts, Federal Civilian Executive Branch (FCEB) agencies in the U.S. are required to apply the patches by February 23, 2023.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/02/cisa-alert-oracle-e-business-suite-and.html