CVE-2012-3152
critical-risk
Published 2012-10-16
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.
Do I need to act?
!
93.5% chance of exploitation in next 30 days
EPSS score — higher than 6% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.1/10
Critical
NETWORK
/ LOW complexity
Affected Products (3)
Affected Vendors
References (23)
Mailing List
http://seclists.org/fulldisclosure/2014/Jan/186
Broken Link
http://www.osvdb.org/86394
Broken Link
http://www.osvdb.org/86395
Broken Link
http://www.securityfocus.com/bid/55955
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/79295
Mailing List
http://seclists.org/fulldisclosure/2014/Jan/186
Broken Link
http://www.osvdb.org/86394
Broken Link
http://www.osvdb.org/86395
Broken Link
http://www.securityfocus.com/bid/55955
and 3 more references
74
/ 100
critical-risk
Severity
31/34 · Critical
Exploitability
34/34 · Critical
Exposure
9/34 · Low