高危
Oracle E-Business Suite服务端请求伪造漏洞
2025-10-12 02:34:51 公开 ,2026-08-04 05:06:42 更新
- CISA KEV
- 关键漏洞
- 勒索软件漏洞
- 远程
- 无需认证
- 公开PoC
- CWE Top 25 (2023)
- CWE Top 25 (2024)
- CWEs:
- CWE-22 (Path Traversal) 、 CWE-287 (Improper Authentication) 、 CWE-444 (HTTP Request/Response Smuggling) 、 CWE-501 (Trust Boundary Violation) 、 CWE-918 (Server-Side Request Forgery (SSRF)) 、 CWE-93 (CRLF Injection)
- CAPEC:
- CAPEC-114 (Authentication Abuse) 、 CAPEC-115 (Authentication Bypass) 、 CAPEC-126 (Path Traversal) 、 CAPEC-15 (Command Delimiters) 、 CAPEC-151 (Identity Spoofing) 、 CAPEC-194 (Fake the Source of Data) 、 CAPEC-22 (Exploiting Trust in Client) 、 CAPEC-273 (HTTP Response Smuggling) 、 CAPEC-33 (HTTP Request Smuggling) 、 CAPEC-57 (Utilizing REST's Trust in the System Resource to Obtain Sensitive Data) 、 CAPEC-593 (Session Hijacking) 、 CAPEC-633 (Token Impersonation) 、 CAPEC-64 (Using Slashes and URL Encoding Combined to Bypass Validation Logic) 、 CAPEC-650 (Upload a Web Shell to a Web Server) 、 CAPEC-664 (Server Side Request Forgery) 、 CAPEC-76 (Manipulating Web Input to File System Calls) 、 CAPEC-78 (Using Escaped Slashes in Alternate Encoding) 、 CAPEC-79 (Using Slashes in Alternate Encoding) 、 CAPEC-81 (Web Server Logs Tampering) 、 CAPEC-94 (Adversary in the Middle (AiTM))
- SSVC:
- 可利用状态:已被积极利用攻击自动化:是技术影响评估:部分 2025-10-17 08:00:00