CVE-2012-3152
Oracle Fusion Middleware Unspecified Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.1
- EPSS
- 98.7% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.05.03
- 공개일
- 2012.10.17
CISA KEV에 등록된 실제 악용 확인 취약점
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute...
공급사 Oracle
제품 Fusion Middleware
영향 버전 n/a, 11.1.1.4.0, 11.1.1.6.0, 11.1.2.0
수정 버전 공식 출처에서 확인 필요
Apply updates per vendor instructions.
조치 기한: 2022.05.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE 미등록
KEV 등록일 2021.11.03
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2012-3152
EPSS 데이터 기준일 2026.06.27