References https://nvd.nist.gov/vuln/detail/cve-2022-21587 https://www.sentinelone.com/vulnerability-database/cve-2022-21587/ https://www.deep-kondah.com/cve-2022-21587-oracle-e-business-suite-unauthenticated-rce-rasp-or-adr/ https://threatprotect.qualys.com/2023/02/09/oracle-e-business-suite-remote-code-execution-vulnerability-cve-2022-21587/ https://www.rapid7.com/blog/post/2023/02/07/etr-cve-2022-21587-rapid7-observed-exploitation-of-oracle-e-business-suite-vulnerability/ https://www.acunetix.com/vulnerabilities/web/oracle-e-business-suite-unauthenticated-remote-code-execution/ https://attackerkb.com/topics/Bkij5kK1qK/cve-2022-21587 https://szybnev.cc/cve-2022-21587-technical-analysis https://autoupdate.ngfw.forcepoint.com/download/dynup/1557-5242-RLNT.html https://autoupdate.ngfw.forcepoint.com/download/dynup/sgpkg-1983-SUMMARY.html https://ccb.belgium.be/advisories/proof-exploit-found-vulnerability-oracle-web-applications-desktop-integrator-product https://www.securityweek.com/exploitation-of-oracle-e-business-suite-vulnerability-starts-after-poc-publication/
Related VulnerabilitiesPoCharman-media-suite-lfi: Harman Media Suite <= 4.2.0 - Local File DisclosurePoCCVE-2026-35273: Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE力合科技-水质监测系统 /AutoData/Business/Report/WQDataCalculation.aspx/Api/ReportList 文件读取漏洞GoCD Cruise /go/add-on/business-continuity/api/cruise_config 信息泄露漏洞孚盟云CRM BusinessPriceReport.aspx SQL注入漏洞孚盟云 CRM /m/Dingding/Product/BusinessPriceReport.aspx SQL 注入漏洞孚盟云CRM /m/Dingding/Ajax/AjaxBusinessPrice.ashx GetBmailByFid SQL 注入漏洞PoCwyse-devicegroup-register: Dell Wyse Management Suite - Unauthenticated Device RegistrationLVS 精益价值管理系统 /Business/LoginVaild.aspx 文件读取漏洞PoC美特 CRM /business/common/toviewspecial.jsp 文件读取漏洞PoC孚盟云CRM /m/Dingding/Ajax/AjaxBusinessPriceActiveReports.ashx GetTempelateList SQL 注入漏洞PoCCVE-2024-13055: Dyn Business Panel Plugin <= 1.0.0 - Cross-Site ScriptingPoCCVE-2020-9314: Oracle iPlanet Web Server 7.0.x - Image Injection