CVE-2022-21587
Description
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Summary dbcve.org
An unauthenticated, network-reachable attacker can exploit a vulnerability in the Upload component of Oracle Web Applications Desktop Integrator (part of Oracle E-Business Suite, versions 12.2.3-12.2.11) via HTTP, with low attack complexity and no user interaction required, leading to full takeover of the component (confidentiality, integrity, and availability all impacted).
Mitigation
Apply the Oracle-published security patch for Oracle E-Business Suite covering Web Applications Desktop Integrator (Upload) at the earliest opportunity; in the interim, restrict network access to the affected Upload endpoint and ensure the host is not exposed to untrusted networks.