Executive brief
An unspecified vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware allows remote attackers to impact confidentiality and integrity. The flaw reportedly involves the URLPARAMETER functionality, which may allow unauthorized reading and uploading of arbitrary files to reports/rwservlet.
Affected products
- Oracle Fusion Middleware - Oracle Reports Developer 11.1.1.4, 11.1.1.6, 11.1.2.0
Timeline
- 2012-10-16: disclosed: Information originally from October 2012 Oracle Critical Patch Update (CPU)
- 2012-10-16: patched: Oracle released the October 2012 Critical Patch Update addressing this issue.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.