Vulnerability Name: | CVE-2012-3153 (CCN-79296) | ||||||||
Assigned: | 2012-10-16 | ||||||||
Published: | 2012-10-16 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. Note: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. Note: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:F/RL:OF/RC:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MISC Type: UNKNOWN http://blog.netinfiltration.com/2013/11/03/oracle-reports-cve-2012-3152-and-cve-2012-3153/ Source: MISC Type: UNKNOWN http://blog.netinfiltration.com/2014/01/19/upcoming-exploit-release-oracle-forms-and-reports-11g/ Source: MITRE Type: CNA CVE-2012-3153 Source: CCN Type: NI @root Oracle Reports Exploits Release Full Disclosure Source: FULLDISC Type: UNKNOWN 20140127 Oracle Reports Exploit - Remote Shell/Dump Passwords Source: EXPLOIT-DB Type: UNKNOWN 31253 Source: MANDRIVA Type: UNKNOWN MDVSA-2013:150 Source: CCN Type: Oracle Web Site Oracle Critical Patch Update Advisory - October 2012 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html Source: BID Type: UNKNOWN 55961 Source: CCN Type: BID-55961 Oracle Fusion Middleware CVE-2012-3153 Remote Security Vulnerability Source: XF Type: UNKNOWN fusionmiddleware-reports-cve20123153(79296) Source: XF Type: UNKNOWN fusionmiddleware-reports-cve20123153(79296) Source: CCN Type: Packet Storm Security [01-28-2014] Oracle Reports Shell Uploader Source: CCN Type: Packet Storm Security [02-18-2014] Oracle Forms / Reports Remote Code Execution | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |