Improper input validation in Oracle Web Applications Desktop Integrator - CVE-2022-21587
Published: October 18, 2022 / Updated: September 27, 2024
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Upload component in Oracle Web Applications Desktop Integrator. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
How to mitigate CVE-2022-21587
Links to Public Exploits and PoC-codes
- Exploit #10534 - Oracle-E-BS-CVE-2022-21587-Exploit (Oracle E-BS CVE-2022-21587 Exploit) (September 27, 2024)
- Exploit #8885 - CVE-2022-21587-Oracle-EBS- (This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)) (March 3, 2023)
- Exploit #8873 - Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload (March 1, 2023)
- Exploit #8831 - Oracle-E-BS-CVE-2022-21587-Exploit (Oracle E-BS CVE-2022-21587 Exploit) (February 12, 2023)
- Exploit #8796 - CVE-2022-21587-POC (CVE-2022-21587 POC ) (February 6, 2023)