VDB
CVE-2022-45378
CVE-2022-45378
PUBLISHED
- Sonstiges - UNIX - Windows
EPSS 4.51% · 89.4th percentile
Risk Scores
EPSS Score
4.51%
89.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Fusion Middleware 8.5.7 | |
| Oracle | Oracle Fusion Middleware 12.2.1.3.0 | |
| Oracle | Oracle Fusion Middleware 14.1.1.0.0 | |
| IBM | IBM FileNet Content Manager 5.5.12 | |
| IBM | IBM FileNet Content Manager 5.6.0 | |
| Oracle | Oracle Fusion Middleware 12.2.1.4.0 | |
| Oracle | Oracle Fusion Middleware 8.5.6 | |
| Oracle | Oracle Fusion Middleware 12.2.1.19.0 | |
| IBM | IBM FileNet Content Manager 5.5.8 |
Exploit Intelligence
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog (certbund)
- https://lists.apache.org/thread/g4l64s283njhnph2otx7q4gs2j952d31 (circl)
- [oss-security] 20221114 CVE-2022-45378: Apache SOAP allows unauthenticated users to potentially invoke arbitrary code (circl)
- https://github.com/d3fudd/CVE-2024-21006_POC (certbund)
Timeline
- Nov 14, 2022 CVE Published
- Nov 15, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 23, 2023 EPSS Score
- May 5, 2023 EPSS Score
- Jun 28, 2023 EPSS Score
- Jul 30, 2023 EPSS Score
- Oct 23, 2023 EPSS Score
- Dec 5, 2023 EPSS Score
- Feb 29, 2024 EPSS Score
- Apr 12, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1637.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1637 advisory
- https://www.oracle.com/security-alerts/cpujul2024.html#AppendixFMW advisory
- https://github.com/k4it0k1d/CVE-2024-21182 advisory
- https://www.ibm.com/support/pages/node/7184867 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0899.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0899 advisory
- https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixFMW advisory
- https://github.com/d3fudd/CVE-2024-21006_POC exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit