Categories
Audio Sources - Full Text Articles

CISA adds Oracle Fusion Middleware flaw to itsĀ Known Exploited Vulnerabilities Catalog

Listen to this article

CISA added a critical flaw impacting Oracle Fusion Middleware, tracked as CVE-2021-35587, to itsĀ Known Exploited Vulnerabilities Catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) a critical vulnerability impacting Oracle Fusion Middleware, tracked as CVE-2021-35587 (CVSS 3.1 Base Score 9.8), to itsĀ Known Exploited Vulnerabilities Catalog.

An unauthenticated attacker with network access via HTTP can exploit the vulnerability to compromise Oracle Access Manager.

ā€œEasily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8ā€ states the NIST.

The flaw was reported in March and affects versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. The IT giant fixed the issue in January with the release of theĀ Critical Patch Update.

ā€œThis vulnerability was discovered by accident by me andĀ PeterjsonĀ while we were analyzing and building PoC for another mega-0day (which is still not fixed by now šŸ˜‰ ).ā€ reads the post published security researcher Nguyen Jang (Janggggg) who reported the flaw alongsideĀ peterjson. ā€œIt’s quiet easy to access the entrypoint and exploit the vulnerability, so it’s recommend to apply the patch now! It may give the attacker access to OAM server, to create any user with any privileges, or just get code execution in the victim’s server.ā€

Below is the video PoC published by Nguyen Jang.

CISA orders federal agencies to fix these vulnerabilities by December 19, 2022.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

PierluigiĀ Paganini

(SecurityAffairs – hacking, CISA)

The post CISA adds Oracle Fusion Middleware flaw to itsĀ Known Exploited Vulnerabilities Catalog appeared first on Security Affairs.