EXPOSURES › CVE-2022-21587
CVE-2022-21587
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.
Oracle E-Business Suite contains an unspecified vulnerability allowing unauthenticated attackers with HTTP network access to compromise Oracle Web Applications Desktop Integrator. DIB organizations using this suite face data exposure and compliance risks if unpatched, especially since the vulnerability is actively exploited in the wild and linked to ransomware. Organizations should immediately upgrade to a patched version and assess their exposure.
Shame score — The vulnerability is unauthenticated, actively exploited in the wild, and linked to ransomware, indicating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |