Executive brief
An unspecified vulnerability in the Upload component of Oracle Web Applications Desktop Integrator allows unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation can lead to a complete takeover of the Oracle Web Applications Desktop Integrator product.
Affected products
- Oracle Web Applications Desktop Integrator 12.2.3-12.2.11
- Oracle E-Business Suite 12.2.3-12.2.11
Timeline
- 2022-10-18: disclosed: NVD Published Date
- 2022-10-18: advisory: Oracle Critical Patch Update Advisory - October 2022
- 2023-02-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-02: exploited: Reported as exploited in the wild by CISA