Intelligence View
CVE-2023-39022 | oscore up to 2.2.6 com.opensymphony.util.EJBUtils.createStateless code injection (EUVD-2023-1997)
A vulnerability, which was classified as critical, has been found in oscore up to 2.2.6. This issue affects some unknown processing of the component com.opensymphony.util.EJBUtils.createStateless. The manipulation leads to code…
The identification of this vulnerability is CVE-2023-39022. The attack can only be initiated within the local network. There is no exploit available.
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - CVE-2023-39022 | oscore up to 2.2.6 com.opensymphony.util.EJBUtils.createStateless code injection (EUVD-2023-1997)
id: cc0591ff-4f60-41e9-9d90-24c34630aed6
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "CVE-2023-39022 | oscore up to " ascii wide
condition:
any of them
}
SOCIAL SHARE CARD GENERATOR