CVE-2022-21500
published 2022-05-20CVE-2022-21500: Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows…
PriorityP184high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
70.59%
99.3th percentile
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
| oracle | user_management | 12.2.4 – 12.2.11 | — |
| oracle_corporation | user_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability resides in the 'Manage Proxies' (Proxy User Delegation) component of Oracle E-Business Suite 12.2, exploitable over HTTP by a self-registered (unauthenticated-at-network-level) user ↗
- →Authentication is technically required but can be bypassed via self-registration; monitor for newly self-registered accounts accessing the Manage Proxies / Proxy User Delegation functionality ↗
- →Oracle E-Business Suite 12.1 is NOT affected; scope detection efforts to 12.2 instances only ↗
- →A nuclei-style HTTP probe checking for a 200 status response on Oracle E-Business Suite endpoints has been associated with this CVE; monitor for automated scanning activity returning HTTP 200 against EBS web interfaces
- ·The attack vector is network (HTTP); no local access or elevated privileges are required beyond self-registration, making internet-exposed EBS 12.2 instances the highest-risk targets ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf87-8ch9-x7hf: Vulnerability in Oracle E-Business Suite (component: Manage Proxies)
ghsa_unreviewed·2022-05-21
CVE-2022-21500 [HIGH] GHSA-vf87-8ch9-x7hf: Vulnerability in Oracle E-Business Suite (component: Manage Proxies)
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
VulnCheck
Oracle E-Business Suite Manage Proxies Information Disclosure
vulncheck·2022·CVSS 7.5
CVE-2022-21500 [HIGH] Oracle E-Business Suite Manage Proxies Information Disclosure
Oracle E-Business Suite Manage Proxies Information Disclosure
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Proxy User Delegation — CVE-2022-21500
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2022-21500 [HIGH] Oracle Oracle E-Business Suite Risk Matrix: Proxy User Delegation — CVE-2022-21500
Oracle Oracle E-Business Suite Risk Matrix: Proxy User Delegation vulnerability
CVE: CVE-2022-21500
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
No detection rules found.
Nuclei
Oracle E-Business Suite <=12.2 - Authentication Bypass
nuclei·CVSS 7.5
CVE-2022-21500 [HIGH] Oracle E-Business Suite <=12.2 - Authentication Bypass
Oracle E-Business Suite '
condition: and
- type: status
status:
- 200
# digest: 490a0046304402201b89fc3c884c4512681d7dcef7e7f45347ad49b4c66465a6e87e7fec1185232502201b5a3e8db034bfdd74c90399f7480e95b9a1235f6cd1e7c9745d3db5dadc254e:922c64590222798bb761d5b6d8e72950
2022-05-20
Published
Exploited in the wild