Junglewise Threat Intelligence

CVE-2022-21587: Oracle E-Business Suite Unspecified Vulnerability

CVE-2022-21587 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-02-02

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Upload component of Oracle Web Applications Desktop Integrator allows unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation can lead to a complete takeover of the Oracle Web Applications Desktop Integrator product.

Affected products

  • Oracle Web Applications Desktop Integrator 12.2.3-12.2.11
  • Oracle E-Business Suite 12.2.3-12.2.11

Timeline

  • 2022-10-18: disclosed: NVD Published Date
  • 2022-10-18: advisory: Oracle Critical Patch Update Advisory - October 2022
  • 2023-02-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-02: exploited: Reported as exploited in the wild by CISA

Related threats