CVE-2022-21587 is a critical vulnerability affecting Oracle Web Applications Desktop Integrator within Oracle E-Business Suite versions 12.2.3 through 12.2.11, specifically in the Upload component. This easily exploitable flaw allows unauthenticated attackers with network access via HTTP to fully compromise the affected system, leading to complete loss of confidentiality, integrity, and availability. With a CVSS score of 9.8, it poses a severe risk. The vulnerability is actively exploited, including in known ransomware campaigns, and exploit code is publicly available via Metasploit modules and Nuclei templates. It has garnered significant community discussion and media coverage, highlighting its widespread impact and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.11CPE matchmatch criteria | cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.