Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-21445-for-12.2.1.3.0-Weblogic — Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup, payload generation, and remote debugging instructions for penetration testing. | Kitploit
Tools/GitHubGitHub/hienkiet/cve-2022-21445-for-12.2.1.3.0-weblogic
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access ToolPayload Development
GitHub
hienkiet/cve-2022-21445-for-12.2.1.3.0-weblogic

CVE-2022-21445-for-12.2.1.3.0-Weblogic

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup, payload generation, and remote debugging instructions for penetration testing.

View Repository
53552 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Overview

CVE-2022-21445 (CVSS 9.8), a vulnerability is an untrusted data deserialization, identified in the ADF Faces component, which can be exploited remotely by attackers without authentication (pre-authentication) to perform RCE.

This vulnerability was discovered by two cybersecurity experts: PeterJson from VNG Corporation and Nguyen Jang from VNPT. Oracle received this report in October 2021 and took 6 months, until April 2022, to release the patch.

In this article, exploitation focuses on Oracle Business Intelligence version 12.2.1.4.0.

Analysis - Reproducing the Vulnerability

Environment Setup

Victim/Target Machine Side

Requirements: Install Windows 10+ Pro or Windows Home (x64) with active license, or use Windows Server (Oracle's products are preferred).

Step 1: Install Java, version jdk 8u112 or later (8Ux), download link: JDKv8U112

  • Add JAVA_HOME with the path pointing to the jdk directory (not jre). Image 1.1: Install Java

Step 2: Install Oracle Database 19c, download link: Oracle 19c

  1. Prepare a folder for database installation, create a path like below and extract the downloaded database zip file into it: C:\app\oracle\product\19c\db_home1

  2. Run setup.application with administrator privileges. Image 2.1: Run DB setup

  3. Follow each step by step as instructed in DB Installation Guide

  4. Important note: At step 8/17, remember to check Create as Container database to open a pluggable database for the upcoming Fusion Middleware installation. Image 2.2: Initialize Pluggable Database

    At step 9/17, select character set as Unicode (AL32UTF8). Image 2.3: Select Unicode

  5. After the installation is complete, carefully check in Windows Services to ensure that the 4 main services as shown below have RUNNING status. Image 2.4: Successful installation

Image 2.5: Check Services

  1. Create a new Oracle database account by following these steps:
  • Terminal Administrator -> sqlplus / as sysdba
  • Create system user: alter user system identified by system_password account unlock;
  • Check existence of system user: select username from dba_users;
  • Set environment: alter session set “_oracle_script”=true;
  • Create regular user hr: create user hr identified by user_password;
  • Grant privileges: grant all privileges to hr;
  • Unlock account – change password: alter user hr identified by hr_pass account unlock;
  • Create new system account: alter user sys identified by sys_pass account unlock;

Step 3: Install SQL Developer, no-jre version, download link: SQLDev-NoJRE Image 3.1: Download SQL Developer

  • Run sqldeveloper.application with administrator privileges. Image 3.2: Launch SQL Developer

  • Configure parameters for a new connection as shown below, note to change Username and Password (as in the example above: hr), Hostname (default is localhost), Port (default is 1521), SID (the global database name installed in step 2). Image 3.3: Configure SQL Developer parameters

  • If when selecting Test you see a Success message, the connection is successful; then select Connect.

Step 4: Install Fusion Middleware Infrastructure (FMW) version 12.2.1.3.0, download link: FMW_ver_12.2.1.3.0 Image 4.1: Download FMW

  • Create a path for the FMW installation directory in the format: C:\Oracle\Middleware\Oracle_Home
  • Follow the instructions step by step: FMW Installation Guide

Step 5: Install Oracle Business Intelligence (OBIEE) version 12.2.1.4.0, download link: OBIEE_ver_12.2.1.4.0

  • Run setup_bi_platform-12.2.1.4.0_win64.exe with administrator privileges. Image 5.1: Run OBIEE installer

  • Install step by step according to OBIEE Installation Guide

  • Note: The BI path must match the FMW installation path, e.g., Oracle/Middleware/Oracle_Home. Image 5.2: BI path must match FMW path

Step 6: Set up BI Schema using the Repository Creation Utility (RCU)

  • At the path C:\Oracle\Middleware\Oracle_Home\oracle_common\bin, run rcu.bat as administrator.

  • Follow the steps below:

Image 6.1: Create Repository

Image 6.2: Database Connection Detail

Image 6.3: Select Component

Image 6.4: Schema Password

  • Finally, click Create to let the system create the BI Schema.

Step 7: Set up environment variables for OBIEE

  • Go to Control Panel > System > Advanced system settings > Advanced > Environment Variables > New System Variable Image 7.1: Environment Variables

Step 8: Create BI Domain

  1. At the path C:\Oracle\Middleware\Oracle_Home\bi\bin, run config.cmd as administrator.

Image 8.1: Run config

  1. In step 1: Select all 3 components, where Essbase is the OLAP server, Business Intelligence Enterprise Edition is BI Analytics, and Business Intelligence Publisher is BI Publisher.

Image 8.2: Select components

  1. In step 3: Configure a new domain as shown below, !! REMEMBER THE DOMAIN PASSWORD BECAUSE IT WILL BE VERY DIFFICULT TO RECOVER. Leave the domain as bi since it's the default.

Image 8.3: Domain account

  1. In step 4: Update domain information for the Database.
Download Tool