Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup, payload generation, and remote debugging instructions for penetration testing.
CVE-2022-21445 (CVSS 9.8), a vulnerability is an untrusted data deserialization, identified in the ADF Faces component, which can be exploited remotely by attackers without authentication (pre-authentication) to perform RCE.
This vulnerability was discovered by two cybersecurity experts: PeterJson from VNG Corporation and Nguyen Jang from VNPT. Oracle received this report in October 2021 and took 6 months, until April 2022, to release the patch.
In this article, exploitation focuses on Oracle Business Intelligence version 12.2.1.4.0.
Requirements: Install Windows 10+ Pro or Windows Home (x64) with active license, or use Windows Server (Oracle's products are preferred).
Step 1: Install Java, version jdk 8u112 or later (8Ux), download link: JDKv8U112

Step 2: Install Oracle Database 19c, download link: Oracle 19c
Prepare a folder for database installation, create a path like below and extract the downloaded database zip file into it: C:\app\oracle\product\19c\db_home1
Run setup.application with administrator privileges.

Follow each step by step as instructed in DB Installation Guide
Important note:
At step 8/17, remember to check Create as Container database to open a pluggable database for the upcoming Fusion Middleware installation.

At step 9/17, select character set as Unicode (AL32UTF8).

After the installation is complete, carefully check in Windows Services to ensure that the 4 main services as shown below have RUNNING status.


Step 3: Install SQL Developer, no-jre version, download link: SQLDev-NoJRE

Run sqldeveloper.application with administrator privileges.

Configure parameters for a new connection as shown below, note to change Username and Password (as in the example above: hr), Hostname (default is localhost), Port (default is 1521), SID (the global database name installed in step 2).

If when selecting Test you see a Success message, the connection is successful; then select Connect.
Step 4: Install Fusion Middleware Infrastructure (FMW) version 12.2.1.3.0, download link: FMW_ver_12.2.1.3.0

Step 5: Install Oracle Business Intelligence (OBIEE) version 12.2.1.4.0, download link: OBIEE_ver_12.2.1.4.0
Run setup_bi_platform-12.2.1.4.0_win64.exe with administrator privileges.

Install step by step according to OBIEE Installation Guide
Note: The BI path must match the FMW installation path, e.g., Oracle/Middleware/Oracle_Home.

Step 6: Set up BI Schema using the Repository Creation Utility (RCU)
At the path C:\Oracle\Middleware\Oracle_Home\oracle_common\bin, run rcu.bat as administrator.
Follow the steps below:




Step 7: Set up environment variables for OBIEE

Step 8: Create BI Domain


