PT-2012-1215 · Oracle · Oracle Reports Developer+1

Miss_Sudo

·

Published

2012-10-16

·

Updated

2025-03-13

·

CVE-2012-3152

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware versions 11.1.1.4 through 11.1.2.0
Description The issue is related to insufficient access control in the Oracle Reports Developer component of Oracle Fusion Middleware. It may allow a remote attacker to impact the integrity and confidentiality of protected information via the HTTP protocol. The vulnerability can potentially be exploited to read and upload arbitrary files, and in combination with other issues, may allow the execution of arbitrary code by uploading a .jsp file.
Recommendations For versions 11.1.1.4 through 11.1.2.0, consider restricting access to the Report Server Component to minimize the risk of exploitation. As a temporary workaround, avoid using the URLPARAMETER functionality in the reports/rwservlet until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05760
CVE-2012-3152

Affected Products

Oracle Fusion Middleware
Oracle Reports Developer