CVE-2022-21587
Summary
| CVE | CVE-2022-21587 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-18 21:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
Risk And Classification
EPSS: 0.943970000 probability, percentile 0.999750000 (date 2026-04-01)
CISA KEV: Listed on 2023-02-02; due 2023-02-23; ransomware use Known
Problem Types: CWE-306
CISA Known Exploited Vulnerability
| Vendor | Oracle |
|---|---|
| Product | E-Business Suite |
| Name | Oracle E-Business Suite Unspecified Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.oracle.com/security-alerts/cpuoct2022.html; https://nvd.nist.gov/vuln/detail/CVE-2022-21587 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | E-business Suite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - October 2022 | MISC | www.oracle.com | |
| Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.