Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.oracle.com/security-alerts/cpuoct2022.html |     | 
History
                    Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 18 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-09-17T14:19:23.174Z
Reserved: 2022-09-02T00:00:00
Link: CVE-2022-39428
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T12:07:42.878Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-10-18T21:15:16.120
Modified: 2024-11-21T07:18:16.050
Link: CVE-2022-39428
 Redhat
                        Redhat
                    No data.