CVE-2012-3152 is a critical vulnerability in Oracle Reports Developer within Oracle Fusion Middleware versions 11.1.1.4, 11.1.1.6, and 11.1.2.0, allowing remote attackers to impact confidentiality and integrity. While Oracle's description is vague, researchers claim it enables arbitrary file reading and uploading via URLPARAMETER functionality, potentially leading to arbitrary code execution when combined with CVE-2012-3153. With a CVSS score of 9.1 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network with no authentication or user interaction required, leading to complete compromise of confidentiality and integrity. It is actively exploited in the wild, with public Metasploit modules and ExploitDB entries available, and has garnered significant community discussion and media coverage, including reports of nation-state actor exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:11.1.1.4.0:*:*:*:*:*:*:* | ||
11.1.1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:11.1.1.6.0:*:*:*:*:*:*:* | ||
11.1.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:11.1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.