漏洞描述
Oracle E-Business Suite (component: Manage Proxies) 12.1 and 12.2 are susceptible to an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise it by self-registering for an account. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
orwaatyat.medium.comhttps://orwaatyat.medium.com/my-new-discovery-in-oracle-e-business-login-panel-that-allowed-to-access-for-all-employees-ed0ec4cad7ac↗twitter.comhttps://twitter.com/GodfatherOrwa/status/1514720677173026816↗www.oracle.comhttps://www.oracle.com/security-alerts/alert-cve-2022-21500.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-21500↗www.oracle.comhttps://www.oracle.com/security-alerts/cpujul2022.html↗