CVE-2022-21587Active Exploitation(oracle / e-business_suite)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch oracle e-business_suite systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-02-23. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • e-business_suite

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
e-business_suite

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-29: 1Active Exploitation · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 106-29
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A critical vulnerability, CVE-2022-21587, in Oracle E-Business Suite is under active exploitation. This flaw allows unauthenticated attackers to upload arbitrary files, potentially leading to full system compromise. Organizations using affected versions (12.2.3 through 12.2.11) should apply Oracle's October 2022 patch immediately to mitigate risks. Timely patch management is crucial to prevent unauthorized access and maintain system integrity. #Oracle #EBS #CVE202221587 #CyberSecurity #PatchNow #InfoSec https://thedailytechfeed.com/critical-oracle-e-business-suite-vulnerability-under-active-exploitation/

    Post summary

    Oracle E-Business Suite CVE-2022-21587 is actively exploited to upload arbitrary files, posing a full system compromise risk. Immediate application of Oracle's October 2022 patch is recommended.

    0000038
    442 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclee-business_suite---

Explore more