cbcvebase.
CVE-2022-21587
published 2022-10-18

CVE-2022-21587: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-02-23
Exploited in the wild
EPSS
98.34%
99.9th percentile
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

2 ranges
VendorProductVersion rangeFixed in
oraclee-business_suite12.2.3 – 12.2.11
oracle_corporationweb_applications_desktop_integrator

Detection & IOCsextracted from sources · hover to see the quote

pathmodules/exploits/linux/http/oracle_ebs_rce_cve_2022_21587.rb
  • CVE-2022-21587 exploitation targets the Oracle Web Applications Desktop Integrator Upload component via unauthenticated HTTP file upload, resulting in RCE as the 'oracle' user on Linux EBS systems (versions 12.2.3–12.2.11). Monitor for unexpected file creation in Oracle EBS web-accessible directories.
  • Post-exploitation of CVE-2022-21587 by Earth Krahang includes deploying web shells on compromised Oracle EBS servers, followed by SoftEther VPN installation with masqueraded process names (taskllst.exe, tasklist.exe, tasklist_32.exe, or curl on Linux).
  • Earth Krahang uses open-source scanning tools (sqlmap, nuclei, xray, vscan, pocsuite, wordpressscan) to identify CVE-2022-21587 and other vulnerabilities on public-facing servers. Detect these tool signatures in network traffic or process execution logs.
  • After exploiting CVE-2022-21587, Earth Krahang performs LSASS dumping via Mimikatz or ProcDump and SAM database dumping (HKLM/sam) for credential harvesting. Monitor for these access patterns on compromised Oracle EBS hosts.
  • Earth Krahang uses certutil commands to download and install SoftEther VPN server on compromised hosts post-exploitation. Monitor for certutil download activity on Oracle EBS servers.
  • ·The vulnerability affects Oracle EBS versions 12.2.3 through 12.2.11 only; the Upload component of Oracle Web Applications Desktop Integrator is the specific attack surface. Scope detection rules accordingly.
  • ·The attack requires no authentication and is exploitable over HTTP from the network (AV:N/AC:L/PR:N/UI:N), meaning perimeter-level HTTP inspection and WAF rules targeting the Upload endpoint are the first line of defense.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.