CVE-2012-3153
Summary
| CVE | CVE-2012-3153 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-16 23:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Fusion Middleware | 11.1.1.4.0 | All | All | All |
| Application | Oracle | Fusion Middleware | 11.1.1.6.0 | All | All | All |
| Application | Oracle | Fusion Middleware | 11.1.2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Upcoming Exploit Release – Oracle Forms and Reports 11g | af854a3a-2127-422b-91ae-364da2661108 | blog.netinfiltration.com | |
| Oracle Forms and Reports 11.1 - Remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Oracle Fusion Middleware CVE-2012-3153 Remote Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Critical Patch Update - October 2012 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Vendor Advisory |
| Oracle Reports CVE-2012-3152 And CVE-2012-3153 | af854a3a-2127-422b-91ae-364da2661108 | blog.netinfiltration.com | |
| Support / Security / Advisories / / MDVSA-2013:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Full Disclosure: Oracle Reports Exploit - Remote Shell/Dump Passwords | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.