CVE-2010-3591 describes an unspecified vulnerability in Oracle Document Capture, part of Oracle Fusion Middleware versions 10.1.3.4 and 10.1.3.5. It carries a critical CVSS score of 9.3, indicating a high potential for remote attackers to compromise confidentiality, integrity, and availability. While Oracle's official description is vague, independent research suggests the vulnerability allows remote attackers to overwrite or delete arbitrary files via insecure methods in the EMPOP3Lib ActiveX component (empop3.dll). Despite its high severity and the existence of public exploit code on ExploitDB, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:10.1.3.4:*:*:*:*:*:*:* | ||
10.1.3.5CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:10.1.3.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.