CVE-2022-39428
Published on: Not Yet Published
Last Modified on: 10/20/2022 05:33:00 AM UTC
Certain versions of Web Applications Desktop Integrator from Oracle contain the following vulnerability:
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2022-39428 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Oracle Corporation - Web Applications Desktop Integrator version = 12.2.3-12.2.11
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - October 2022 | www.oracle.com text/html |
![]() |
Related QID Numbers
- 730670 Oracle E-Business Suite Multiple Security Vulnerabilities (CPUOCT2022)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Oracle | Web Applications Desktop Integrator | All | All | All | All |
- cpe:2.3:a:oracle:web_applications_desktop_integrator:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-39428 : Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite… twitter.com/i/web/status/1… | 2022-10-18 21:36:23 |
![]() |
CVE-2022-39428 | 2022-10-18 22:39:02 |