
CVE-2021-35587の概念実証エクスプロイト。Oracle Access Managerにおける未認証のリモートコード実行の脆弱性であり、影響を受けるシステムの完全な乗っ取りを可能にします。
** 参考情報 - 参照ソース - [[https://testbnull.medium.com/oracle-access-manager-pre-auth-rce-cve-2021-35587-analysis-1302a4542316][Oracle Access Manager pre-authentication Remote Code Execution CVE-2020-35587]] - [[https://github.com/cckuailong/reapoc/blob/4eb15938ed9f44aa7db47fdbb88bc45f556b02bb/2021/CVE-2021-35587/poc/nuclei/CVE-2021-35587.yaml][Nuclei POC ]] - リスク参照 - [[https://nvd.nist.gov/vuln/detail/CVE-2021-35587][NVD]] - CVE - [[https://github.com/CVEProject/cvelist/blob/master/2021/35xxx/CVE-2021-35587.json][CVE-2021-35587]] - [[https://nvd.nist.gov/vuln/detail/CVE-2021-35587][NVD]] - POCエンジン参照 - [[https://github.com/antx-code/pocx][pocx]]