超危
Oracle E-Business Suite代码执行漏洞
2025-10-05 03:17:01 公开 ,2026-08-04 05:07:14 更新
- 勒索软件漏洞
- CISA KEV
- 关键漏洞
- 无需认证
- 远程
- 公开PoC
- CWE Top 25 (2023)
- CWE Top 25 (2024)
- CWEs:
- CWE-22 (Path Traversal) 、 CWE-287 (Improper Authentication) 、 CWE-444 (HTTP Request/Response Smuggling) 、 CWE-611 (Improper Restriction of XML External Entity Reference) 、 CWE-91 (XML Injection (aka Blind XPath Injection)) 、 CWE-918 (Server-Side Request Forgery (SSRF)) 、 CWE-93 (CRLF Injection)
- CAPEC:
- CAPEC-126 (Path Traversal) 、 CAPEC-15 (Command Delimiters) 、 CAPEC-221 (Data Serialization External Entities Blowup) 、 CAPEC-250 (XML Injection) 、 CAPEC-273 (HTTP Response Smuggling) 、 CAPEC-33 (HTTP Request Smuggling) 、 CAPEC-64 (Using Slashes and URL Encoding Combined to Bypass Validation Logic) 、 CAPEC-664 (Server Side Request Forgery) 、 CAPEC-76 (Manipulating Web Input to File System Calls) 、 CAPEC-78 (Using Escaped Slashes in Alternate Encoding) 、 CAPEC-79 (Using Slashes in Alternate Encoding) 、 CAPEC-81 (Web Server Logs Tampering) 、 CAPEC-83 (XPath Injection)
- SSVC:
- 可利用状态:已被积极利用攻击自动化:是技术影响评估:全部 2025-10-06 08:00:00