.. / CVE-2022-21500

Exploit for Oracle E-Business Suite <=12.2 - Authentication Bypass (CVE-2022-21500)

Description:

Oracle E-Business Suite (component: Manage Proxies) 12.1 and 12.2 are susceptible to an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise it by self-registering for an account. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data.

Nuclei Template

View the template here CVE-2022-21500.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-21500.yaml
Copy

References:

https://www.oracle.com/security-alerts/alert-cve-2022-21500.html
https://nvd.nist.gov/vuln/detail/CVE-2022-21500
https://www.oracle.com/security-alerts/cpujul2022.html
https://orwaatyat.medium.com/my-new-discovery-in-oracle-e-business-login-panel-that-allowed-to-access-for-all-employees-ed0ec4cad7ac
https://twitter.com/GodfatherOrwa/status/1514720677173026816