Priority reviewCritical
CVE-2022-22916
o2oa
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
- CVSS
- 9.8
- EPSS
- 38.4% 98.4% percentile
- CISA KEV
- Not listed
- Published
- 2022.02.18
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
FIRST EPSS indicates an elevated probability of exploitation.
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
Confirm exposure before applying a vendor-supported change.
Confirm that o2oa and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.