Ensure Oracle E-Business Suite is patched against CVE-2022-21587 .
Look for unusual ZIP extractions in system logs or the presence of .jsp files in unexpected directories like /OA_HTML/ . hAX.zip
Security researchers often structure this ZIP file to exploit the extraction process: hAX.zip
Help you has been targeted by this exploit? Oracle CVE-2022-21587 Technical Analysis - Zybnev Sergey hAX.zip