Junglewise Threat Intelligence

CVE-2012-3152: Oracle Fusion Middleware Unspecified Vulnerability

CVE-2012-3152 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle Fusion Middleware. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware allows remote attackers to impact confidentiality and integrity. The flaw reportedly involves the URLPARAMETER functionality, which may allow unauthorized reading and uploading of arbitrary files to reports/rwservlet.

Affected products

  • Oracle Fusion Middleware - Oracle Reports Developer 11.1.1.4, 11.1.1.6, 11.1.2.0

Timeline

  • 2012-10-16: disclosed: Information originally from October 2012 Oracle Critical Patch Update (CPU)
  • 2012-10-16: patched: Oracle released the October 2012 Critical Patch Update addressing this issue.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.

Related threats