CISA added a critical flaw impacting Oracle Fusion Middleware, tracked as CVE-2021-35587, to itsĀ Known Exploited Vulnerabilities Catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) a critical vulnerability impacting Oracle Fusion Middleware, tracked as CVE-2021-35587 (CVSS 3.1 Base Score 9.8), to itsĀ Known Exploited Vulnerabilities Catalog.
An unauthenticated attacker with network access via HTTP can exploit the vulnerability to compromise Oracle Access Manager.
āEasily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8ā states the NIST.
The flaw was reported in March and affects versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. The IT giant fixed the issue in January with the release of theĀ Critical Patch Update.
āThis vulnerability was discovered by accident by me andĀ PeterjsonĀ while we were analyzing and building PoC for another mega-0day (which is still not fixed by now
).ā reads the post published security researcher Nguyen Jang (Janggggg) who reported the flaw alongsideĀ peterjson. āItās quiet easy to access the entrypoint and exploit the vulnerability, so itās recommend to apply the patch now! It may give the attacker access to OAM server, to create any user with any privileges, or just get code execution in the victimās server.ā
Below is the video PoC published by Nguyen Jang.
CISA orders federal agencies to fix these vulnerabilities by December 19, 2022.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
|
|
(SecurityAffairsĀ ā hacking, CISA)
The post CISA adds Oracle Fusion Middleware flaw to itsĀ Known Exploited Vulnerabilities Catalog appeared first on Security Affairs.
