S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-21587 Scanner

CVE-2022-21587 scanner - Remote Code Execution (RCE) vulnerability in Oracle Web Applications Desktop Integrator

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
65
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-21587
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Web Applications Desktop Integratorby Oracle Corporation
12.2.3-12.2.11
Updated Aug 22, 2026View on NVD →
Detail

Oracle Web Applications Desktop Integrator, or simply WADL, is a product offered by Oracle E-Business Suite. It is a tool that facilitates the integration of Excel spreadsheets with Oracle's business applications. This product, which is commonly utilized in corporate finance departments, enables users to access real-time data, create reports, and upload them via a simple Excel interface. WADL streamlines these processes and eliminates the need for professionals to conduct manual data transfers, saving them significant time and effort. 

Recently, a vulnerability has been discovered in WADL, identified as CVE-2022-21587. The flaw has been present in supported versions ranging from 12.2.3 to 12.2.11 and can be easily exploitable by an unauthorized party with network access using HTTP communication protocols. The vulnerability revolves around the Upload component, which is a crucial feature of WADL. An attacker could potentially infiltrate the system through this vulnerability, leading to a takeover of WADL. 

Once this vulnerability is exploited, it could result in dire consequences. The impacts of CVE-2022-21587 include confidentiality breaches, integrity compromises, and availability issues. If hackers gain access to WADL, they may have access to sensitive financial data and other confidential or sensitive information, potentially leading to a loss of revenue, legal repercussions, or damage to a company's reputation. 

s4e.io platform, with its pro features, allows users to stay updated on threats to their digital assets, including vulnerabilities in their systems. The platform provides real-time scans for known vulnerabilities and ensures that users are notified swiftly, allowing them to fix any issue that may arise, making it the best choice for proactive security measures. By utilizing this platform, businesses can remain protected and prepared for any potential threats that may come their way.

 

REFERENCES

Solution Advice

Organizations that use WADL must take precautions to ensure their system's security by employing the following measures:

  • Disable External Access to the network where WADL is installed.
  • Employ Firewall rules to restrict access to network FTP connections that WADL uses.
  • Apply Oracle patches as soon as available to mitigate known vulnerabilities.
  • Disable WADL or operational modes that rely on the Desktop tier to process transactional data.
  • Secure WADL components’ passwords and restrict access to configuration files necessary for operation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.