LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-21587: Oracle E-Business Suite Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 2, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 23, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-21587 to its Known Exploited Vulnerabilities catalog on Feb 2, 2023, with a federal patch deadline of Feb 23, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

CVE-2022-21587 is an unspecified vulnerability in Oracle E-Business Suite that lets an unauthenticated attacker with network access over HTTP compromise the Oracle Web Applications Desktop Integrator component. Because the weakness is missing authentication for a critical function (CWE-306), remote attackers can reach sensitive functionality without credentials. CISA notes that this vulnerability has been used by ransomware operators, so organizations running the product should treat it as high priority and confirm all details against the vendor advisory.

For IT and security teams, the risk is straightforward: an exposed Oracle E-Business Suite instance can be fully compromised by anyone who can reach it on the network, leading to data theft, lateral movement, or ransomware deployment. Immediate inventory and patching are required.

How it works

The vulnerability belongs to the class of missing authentication for critical functions (CWE-306). In practical terms, a critical part of the Oracle Web Applications Desktop Integrator does not properly require the caller to prove identity before allowing access. An attacker who can send HTTP requests to the affected component can therefore invoke that functionality as if they were a legitimate user.

Because the flaw is unspecified beyond the CISA description, exact request paths, parameters, or payload formats are not public in the provided facts. Defenders should assume that any unauthenticated HTTP interaction with the Web Applications Desktop Integrator could be abused to achieve compromise of that component and, by extension, the broader E-Business Suite environment. Confirm the precise attack surface and any additional technical details solely against Oracle’s advisory.

Am I affected? How to find it in your systems

Oracle E-Business Suite is typically deployed as an enterprise ERP platform, often in data centers or private clouds, and is accessed by finance, HR, and supply-chain users. The vulnerable component is the Web Applications Desktop Integrator, which is commonly exposed over HTTP/HTTPS for desktop integration features.

Any system that matches the product and has not yet received the vendor-supplied update should be treated as potentially affected until proven otherwise.

How to remediate

The primary remediation is to apply the security updates published by Oracle for this vulnerability. Follow the CISA-required action: apply updates per vendor instructions. Obtain the correct patch or Critical Patch Update from Oracle’s support portal, test it in a non-production environment if possible, then deploy it to production as quickly as change-control processes allow.

If you can't patch immediately

If immediate patching is blocked by operational constraints, implement compensating controls to reduce exposure until the update can be applied.

These measures lower risk but do not eliminate it; schedule the official patch as soon as feasible.

If your data may have been exposed

Because this vulnerability is known to have been used by ransomware groups, successful exploitation can lead to full system compromise and subsequent data theft or encryption. If you discover evidence of exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected systems, preserve logs, and begin forensic investigation. Organizations can also run a free exposure scan of their email addresses against known breach data sets to check whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · E-Business Suite
WeaknessCWE-306
Added to CISA KEVFeb 2, 2023
Federal patch deadlineFeb 23, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities