you are viewing a single comment's thread
view the rest of the comments
[–] 9 points 1 day ago (1 child)

It's pretty common in a killchain following a server side request forgery since the traffic isn't seem by the WAF.

Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 1 day ago (1 child)

    It really is not common in the common era.

    E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as "enterprise" to any required insurance, even then.

    Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.

  • source
  • parent
  • hideshow 2 child comments