CVE-2022-21587
published 2022-10-18CVE-2022-21587: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-02-23
Exploited in the wild
EPSS
98.34%
99.9th percentile
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | 12.2.3 – 12.2.11 | — |
| oracle_corporation | web_applications_desktop_integrator | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-21587 exploitation targets the Oracle Web Applications Desktop Integrator Upload component via unauthenticated HTTP file upload, resulting in RCE as the 'oracle' user on Linux EBS systems (versions 12.2.3–12.2.11). Monitor for unexpected file creation in Oracle EBS web-accessible directories. ↗
- →Post-exploitation of CVE-2022-21587 by Earth Krahang includes deploying web shells on compromised Oracle EBS servers, followed by SoftEther VPN installation with masqueraded process names (taskllst.exe, tasklist.exe, tasklist_32.exe, or curl on Linux). ↗
- →Earth Krahang uses open-source scanning tools (sqlmap, nuclei, xray, vscan, pocsuite, wordpressscan) to identify CVE-2022-21587 and other vulnerabilities on public-facing servers. Detect these tool signatures in network traffic or process execution logs. ↗
- →After exploiting CVE-2022-21587, Earth Krahang performs LSASS dumping via Mimikatz or ProcDump and SAM database dumping (HKLM/sam) for credential harvesting. Monitor for these access patterns on compromised Oracle EBS hosts. ↗
- →Earth Krahang uses certutil commands to download and install SoftEther VPN server on compromised hosts post-exploitation. Monitor for certutil download activity on Oracle EBS servers. ↗
- ·The vulnerability affects Oracle EBS versions 12.2.3 through 12.2.11 only; the Upload component of Oracle Web Applications Desktop Integrator is the specific attack surface. Scope detection rules accordingly. ↗
- ·The attack requires no authentication and is exploitable over HTTP from the network (AV:N/AC:L/PR:N/UI:N), meaning perimeter-level HTTP inspection and WAF rules targeting the Upload endpoint are the first line of defense. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-64x7-wh2p-524g: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload)
ghsa_unreviewed·2022-10-19
CVE-2022-21587 [CRITICAL] CWE-306 GHSA-64x7-wh2p-524g: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload)
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle E-Business Suite Unspecified Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-21587 [CRITICAL] CWE-306 Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Affected: Oracle E-Business Suite
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://go.crowdstrike.com/rs/281-OBQ-266/images/report-crowdstrike-2023-threat-hunting-report.pdf; https://information.rapid7.com/rs/411-NAK-970/images/Rapid7-2023-Mid-Year-Threat-Review.pdf; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-03&host_type=src&vulnerability=cve-2022-
CISA
Oracle E-Business Suite Unspecified Vulnerability
cisa·2023-02-02·CVSS 9.8
CVE-2022-21587 [CRITICAL] CWE-306 Oracle E-Business Suite Unspecified Vulnerability
Vulnerability: Oracle E-Business Suite Unspecified Vulnerability
Affected: Oracle E-Business Suite
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Required Action: Apply updates per vendor instructions.
Notes: https://www.oracle.com/security-alerts/cpuoct2022.html; https://nvd.nist.gov/vuln/detail/CVE-2022-21587
Remediation Due Date: 2023-02-23
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Upload — CVE-2022-21587
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2022-21587 [CRITICAL] Oracle Oracle E-Business Suite Risk Matrix: Upload — CVE-2022-21587
Oracle Oracle E-Business Suite Risk Matrix: Upload vulnerability
CVE: CVE-2022-21587
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneDownloadService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044012; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneOfflineLOVService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044013; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneViewerXMLService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044011; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneUploaderService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044010; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
Metasploit
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
metasploit
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
This module exploits an unauthenticated arbitrary file upload vulnerability in Oracle Web Applications Desktop Integrator, as shipped with Oracle EBS versions 12.2.3 through to 12.2.11, in order to gain remote code execution as the oracle user.
Nuclei
Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2022-21587 [CRITICAL] Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
Oracle E-Business Suite 12.2.3 through 12.2.11 is susceptible to remote code execution via the Oracle Web Applications Desktop Integrator product, Upload component. An attacker with HTTP network access can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: CVE-2022-21587
info:
name: Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
author: rootxharsh,iamnoooob,pdresearch,dogasantos,s4e-io
severity: critical
description: |
Oracle E-Business Suite 12.2.3 through 12.2.11 is susceptible to remote code execution via the Oracle Web Applications Desktop Integrator product, Upload component. An attacker w
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18·CVSS 9.8
[CRITICAL] Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT & Targeted Attacks
## Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi 2024/03/18 Read time: ( words)
Save to Folio
One of the infection vectors used involves the scanning of public-facing servers. Earth Krahang heavily employs open-source scanning tools that perform recursive searches of folders such as .git or .idea . The threat actor also resorts to simply brute-forcing directories to help identify files that may contain sensitive information such as file paths or passwords on the victim’s servers. They also tend t
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT & Targeted Attacks
# Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi
2024/03/18
Read time: ( words)
Save to Folio
## Introduction
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa. The threat actor exploits public-facing servers and sends spear phishing emails to deliver previously unseen backdoors.
Our research allowed us to identify the campaign’s multiple connect
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18·CVSS 9.8
[CRITICAL] Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT & Targeted Attacks
## Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi Mar 18, 2024 Read time: ( words)
Save to Folio
One of the infection vectors used involves the scanning of public-facing servers. Earth Krahang heavily employs open-source scanning tools that perform recursive searches of folders such as .git or .idea . The threat actor also resorts to simply brute-forcing directories to help identify files that may contain sensitive information such as file paths or passwords on the victim’s servers. They also tend
Bleepingcomputer
Chinese Earth Krahang hackers breach 70 orgs in 23 countries
blogs_bleepingcomputer·2024-03-18·CVSS 9.8
[CRITICAL] Chinese Earth Krahang hackers breach 70 orgs in 23 countries
## Chinese Earth Krahang hackers breach 70 orgs in 23 countries
## Bill Toulas
A sophisticated hacking campaign attributed to a Chinese Advanced Persistent Threat (APT) group known as 'Earth Krahang' has breached 70 organizations and targeted at least 116 across 45 countries.
According to Trend Micro researchers monitoring the activity, the campaign has been underway since early 2022 and focuses primarily on government organizations.
Specifically, the hackers have compromised 48 government organizations, 10 of which are Foreign Affairs ministries, and targeted another 49 government agencies.
The attackers exploit vulnerable internet-facing servers and use spear-phishing emails to deploy custom backdoors for cyberespionage.
Earth Krahang abuses its presence on breached government infr
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18·CVSS 9.8
[CRITICAL] Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT & Targeted Attacks
## Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi Mar 18, 2024 Read time: ( words)
Save to Folio
One of the infection vectors used involves the scanning of public-facing servers. Earth Krahang heavily employs open-source scanning tools that perform recursive searches of folders such as .git or .idea . The threat actor also resorts to simply brute-forcing directories to help identify files that may contain sensitive information such as file paths or passwords on the victim’s servers. They also tend
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18·CVSS 9.8
[CRITICAL] Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT y ataques dirigidos
## Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi Mar 18, 2024 Read time: ( words)
Save to Folio
One of the infection vectors used involves the scanning of public-facing servers. Earth Krahang heavily employs open-source scanning tools that perform recursive searches of folders such as .git or .idea . The threat actor also resorts to simply brute-forcing directories to help identify files that may contain sensitive information such as file paths or passwords on the victim’s servers. They also ten
Trendmicro
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
blogs_trendmicro·2024-03-18·CVSS 9.8
[CRITICAL] Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
APT und gezielte Angriffe
## Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.
By: Joseph C Chen, Daniel Lunghi Mar 18, 2024 Read time: ( words)
Save to Folio
One of the infection vectors used involves the scanning of public-facing servers. Earth Krahang heavily employs open-source scanning tools that perform recursive searches of folders such as .git or .idea . The threat actor also resorts to simply brute-forcing directories to help identify files that may contain sensitive information such as file paths or passwords on the victim’s servers. They also t
http://packetstormsecurity.com/files/171208/Oracle-E-Business-Suite-EBS-Unauthenticated-Arbitrary-File-Upload.htmlhttps://www.oracle.com/security-alerts/cpuoct2022.htmlhttp://packetstormsecurity.com/files/171208/Oracle-E-Business-Suite-EBS-Unauthenticated-Arbitrary-File-Upload.htmlhttps://www.oracle.com/security-alerts/cpuoct2022.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21587
2022-10-18
Published
2023-02-02
Added to CISA KEV
Exploited in the wild