CVE-2022-29937
Last modified
CVE-2022-29937 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked. NOTE: this is not an Oracle Corporation product.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked. NOTE: this is not an Oracle Corporation product.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Usu | Oracle Optimization | 20210817 |
References
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-xw3r-mq8p-fjv5Exploit, Third Party Advisory
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-xw3r-mq8p-fjv5Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29937?
How severe is CVE-2022-29937?
How do I fix CVE-2022-29937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29931The administration interface of the Raytion Custom Security …6.1
- CVE-2022-29932The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) …7.5
- CVE-2022-29933Craft CMS through 3.7.36 allows a remote unauthenticated att…8.8
- CVE-2022-29934USU Oracle Optimization before 5.17.5 lacks Polkit authentic…7.8
- CVE-2022-29935USU Oracle Optimization before 5.17.5 allows attackers to di…7.5
- CVE-2022-29936USU Oracle Optimization before 5.17 allows authenticated qua…8.8
- CVE-2022-29938In LibreHealth EHR 2.0.0, lack of sanitization of the GET pa…8.8
- CVE-2022-29939In LibreHealth EHR 2.0.0, lack of sanitization of the GET pa…5.4
- CVE-2022-29940In LibreHealth EHR 2.0.0, lack of sanitization of the GET pa…5.4
- CVE-2022-29942Talend Administration Center has a vulnerability that allows…6.5
- CVE-2022-29943Talend Administration Center has a vulnerability that allows…6.5
- CVE-2022-29944An issue was discovered in ONOS 2.5.1. There is an incorrect…5.3
Are you affected by CVE-2022-29937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
