PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2024

CVE-2012-3152 & CVE-2012-3153 Scanner

CVE-2012-3152 & CVE-2012-3153 scanner - Remote Code Execution (RCE) vulnerability in Oracle Reports Developer component in Oracle Fusion Middleware

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-3153
6.4
CVSS

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Oracle Reports Developer component is a part of the Oracle Fusion Middleware, which is an integrated platform that allows for the development, deployment, and management of applications. Specifically, the Reports Developer component is used for creating and generating reports that extract data from databases and present it in various formats. This can be used for a multitude of purposes, such as business intelligence, financial reporting, and analytics.

Two of the vulnerabilities that has been detected in the Oracle Reports Developer component are CVE-2012-3152 and CVE-2012-3153. These vulnerabilities allows remote attackers to affect the confidentiality and integrity of the system by exploiting unknown vectors related to the Report Server Component. The precise details of the vectors have not been disclosed, but it has been documented that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet. This issue has been found to occur in earlier versions of the Reports Developer component as well.

Exploiting this vulnerability can lead to numerous consequences, including data theft and loss, unauthorized access to sensitive information, and the possibility of arbitrary code execution. By uploading a .jsp file, attackers can execute arbitrary code on the affected system, allowing them to gain further access and control over it.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. Our platform provides comprehensive vulnerability scanning and reporting, as well as expert guidance and support, to ensure that your systems are fully protected against the latest threats. With s4e.io, you can rest assured that your data and systems are in safe hands.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Applying the latest security patches and updates as soon as they become available
  • Implementing access controls and deploying firewalls to restrict traffic to and from the system
  • Disabling unnecessary services and features that could potentially be exploited
  • Conducting regular security audits and vulnerability scans to identify and address any potential weaknesses
  • Educating users on safe browsing habits and best practices for online security

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2012-3152 & CVE-2012-3153 scanner - Remote Code Execution (RCE) vulnerability in Oracle Reports Developer component in Oracle Fusion Middleware | S4E