CVE-2022-22916
O2OA RCE Vulnerability in Jaxrs Invoke Endpoint.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
O2OA, a web-based enterprise application platform, has a critical remote code execution vulnerability in its `/x_program_center/jaxrs/invoke` endpoint. This allows unauthenticated attackers to run arbitrary commands on a reachable server, potentially compromising systems and sensitive data. Confirming O2OA usage and ex