Skip to content
COOEY

EXPOSURES › CVE-2022-21587

CVE-2022-21587

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-21587 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.

Oracle E-Business Suite contains an unspecified vulnerability allowing unauthenticated attackers with HTTP network access to compromise Oracle Web Applications Desktop Integrator. DIB organizations using this suite face data exposure and compliance risks if unpatched, especially since the vulnerability is actively exploited in the wild and linked to ransomware. Organizations should immediately upgrade to a patched version and assess their exposure.

Shame score — The vulnerability is unauthenticated, actively exploited in the wild, and linked to ransomware, indicating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized