← Vulnerability feed

Vulnerability record · CVE-2022-21500 · published 20 May 2022

CVE-2022-21500: Oracle E-Business Suite Manage Proxies unauthenticated data access

Oracle · E Business Suite

Oracle E-Business Suite 12.2 contains a flaw in the Manage Proxies component that allows an attacker to reach critical data without prior authentication. The record gives no root-cause detail (CWE is listed as insufficient information), so the exact mechanism is unknown. Because the affected component governs proxy configuration, exposure of that data can be significant to the application's security posture.

7.5 CVSS 3.1 High EPSS 72% · top 0.6%
7.5CVSS 3.1 base score, v2 5.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.5 with a network, no-privilege, no-interaction vector and a very high EPSS score, though no confirmed in-the-wild exploitation is documented.

What it is

Oracle E-Business Suite 12.2 contains a flaw in the Manage Proxies component that allows an attacker to reach critical data without prior authentication. The record gives no root-cause detail (CWE is listed as insufficient information), so the exact mechanism is unknown. Because the affected component governs proxy configuration, exposure of that data can be significant to the application's security posture.

Impact

An attacker can read critical data or all data accessible through Oracle E-Business Suite, a confidentiality-only impact with no integrity or availability effect. The CVSS vector rates confidentiality as high.

Attack surface

Reachable over the network via HTTP with no user interaction and no privileges required per the CVSS vector. The description notes authentication is required for a successful attack but that the user may be self-registered, so a self-service account may be enough to reach the vulnerable component.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high at roughly 0.72 (99th percentile), indicating elevated predicted exploitation activity. No ransomware association is documented.

What to do

  • Apply the Oracle CPU July 2022 patch referenced in the advisory and patch availability document.
  • Restrict network access to the E-Business Suite HTTP interface to trusted networks or VPN.
  • Disable or tightly control self-registration so unauthenticated users cannot obtain accounts.
  • Review and lock down Manage Proxies configuration and proxy-related privileges.
  • Monitor for anomalous access to proxy configuration endpoints.

Detection

  • Alert on HTTP requests to Manage Proxies endpoints from unauthenticated or newly self-registered sessions.
  • Baseline normal access to proxy configuration pages and flag deviations by source IP and account age.
  • Correlate E-Business Suite audit logs for proxy configuration reads with account creation events.
  • Watch for scanning or enumeration of EBS HTTP paths preceding access to the Manage Proxies component.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2022-21587Oracle E-Business Suite Desktop Integrator unauthenticated file upload RCEOracle Web Applications Desktop Integrator in Oracle E-Business Suite (versions 12.2.3-12.2.11) fails to require authentication for a critical upload…KEVEPSS 98%analysed10.0CVE-2015-4839Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.8%10.0CVE-2015-4798Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.9%10.0CVE-2008-1826Oracle e-business suite vulnerabilityMultiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka…EPSS 2.2%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2022-21500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.