V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-21587
CVE
Critical KEVConfirmedExploit available

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions …

CVSS
9.8
Critical
EPSS
0.98
p99
Published
2022-01-01
Updated
2023-02-02
Description

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Tags · CWE
KEVPre-auth
CWE-306
CAPEC-12
CAPEC-36
CAPEC-62
CAPEC-166
CAPEC-216
Affected products
E-business_suite 12.2.3–12.2.11
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2023-02-02
Added to KEV
2023-02-02
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.983 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2022-21587
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected products
ProductVendorStatus
e-business_suite*Exploited
Source databases
CVE
Related vulnerabilities