CVE-2023-21587
published 2023-01-13CVE-2023-21587: Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.41%
33.4th percentile
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | indesign | — | — |
| adobe | indesign | 17.0 – 17.4 | — |
| adobe | indesign | unspecified – 18.0 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9pg6-chjx-xpmr: Adobe InDesign version 18
ghsa_unreviewed·2023-01-13
CVE-2023-21587 [HIGH] CWE-122 GHSA-9pg6-chjx-xpmr: Adobe InDesign version 18
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CISA
Oracle E-Business Suite Unspecified Vulnerability
cisa·2023-02-02·CVSS 9.8
CVE-2022-21587 [CRITICAL] CWE-306 Oracle E-Business Suite Unspecified Vulnerability
Vulnerability: Oracle E-Business Suite Unspecified Vulnerability
Affected: Oracle E-Business Suite
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Required Action: Apply updates per vendor instructions.
Notes: https://www.oracle.com/security-alerts/cpuoct2022.html; https://nvd.nist.gov/vuln/detail/CVE-2022-21587
Remediation Due Date: 2023-02-23
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneViewerXMLService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044011; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneDownloadService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044012; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneOfflineLOVService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044013; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneUploaderService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044010; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
No public exploits indexed.
No writeups or analysis indexed.
2023-01-13
Published