CVE-2022-21500

EBS Manage Proxies Authentication Bypass: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published May 20, 2022 · Updated March 4, 2026

Mitigated by Waratek HIGH CVSS 7.5 v3.1

The vulnerability

Unauthorized data access via self-registered user account

Oracle E-Business Suite's Manage Proxies component only checks that a request comes from an authenticated session, not whether that account was ever vetted, so an attacker can self-register a new user through EBS's own sign-up flow and use it to reach Manage Proxies and pull sensitive data. No real credentials, insider access, or admin approval are needed, just the ability to create an account.

Affected softwareOracle E-Business Suite (User Management / Manage Proxies)
Affected versions12.2 (User Management component 12.2.4 through 12.2.11)
WeaknessBroken authentication (self-registration bypass)
Published2022-05-20
SeverityHIGH · CVSS 7.5

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

EBS Manage Proxies Authentication Bypass FAQ

Is EBS Manage Proxies Authentication Bypass (CVE-2022-21500) exploitable?

CVE-2022-21500 carries a CVSS 7.5/10 (HIGH) rating and affects Oracle E-Business Suite (User Management / Manage Proxies) 12.2 (User Management component 12.2.4 through 12.2.11). Oracle E-Business Suite's Manage Proxies component only checks that a request comes from an authenticated session, not whether that account was ever vetted, so an attacker can self-register a new user through EBS's own sign-up flow and use it to reach Manage Proxies and pull sensitive data. No real credentials, insider access, or admin approval are needed, just the ability to create an account.

How does Waratek mitigate EBS Manage Proxies Authentication Bypass (CVE-2022-21500)?

Waratek RASP blocks exploitation of EBS Manage Proxies Authentication Bypass (CVE-2022-21500) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was EBS Manage Proxies Authentication Bypass (CVE-2022-21500) exploited after disclosure?

A working exploit for CVE-2022-21500 appeared within 752 days of its NVD disclosure, on June 9, 2024.

Protect your apps in production

Get protected against EBS Manage Proxies Authentication Bypass - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2022-21500 and attacks like it, and get you covered in production.