Vulnerability record · CVE-2012-0518 · published 16 October 2012
CVE-2012-0518: Oracle Fusion Middleware SSO open redirect flaw
Oracle · Fusion Middleware
Oracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked as CWE-601. The flaw lets remote attackers influence redirect targets, which matters because SSO redirects are trusted by users and can be abused for phishing or credential theft. The description is thin and does not identify the exact vectors or code path.
Description
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with confirmed in-the-wild exploitation, but its CVSS impact is limited to integrity with required user interaction.
What it is
Oracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked as CWE-601. The flaw lets remote attackers influence redirect targets, which matters because SSO redirects are trusted by users and can be abused for phishing or credential theft. The description is thin and does not identify the exact vectors or code path.
Impact
An attacker can redirect a victim to an attacker-controlled site through the trusted SSO endpoint, enabling phishing or credential harvesting. Integrity impact is limited; there is no confidentiality or availability impact per the CVSS vector.
Attack surface
Reachable over the network via the SSO redirect handling with no authentication required, but exploitation requires user interaction (UI:R) since a victim must follow the crafted redirect. The scope is changed (S:C), meaning the redirect can affect resources beyond the vulnerable component.
Exploitation
Listed in CISA KEV since 2022-03-28, indicating known exploitation in the wild, though no ransomware use is documented. EPSS 30-day probability is about 4.7 percent (91st percentile), and the only vendor reference is the October 2012 CPU patch advisory.
What to do
- Apply the Oracle Critical Patch Update from October 2012 (cpuoct2012-1515893) or a later CPU that supersedes it.
- If the affected 10.1.4.3.0 SSO component cannot be patched, restrict or disable external redirect handling and validate redirect targets against an allowlist.
- Place the SSO endpoint behind a reverse proxy or WAF rule that blocks off-domain redirect parameters.
- Monitor and log SSO redirect responses, alerting on Location headers pointing outside approved domains.
- Review for exposure of the legacy 10.1.4.3.0 deployment and plan migration off end-of-life Fusion Middleware.
Detection
- Search web and proxy logs for requests to the SSO redirect endpoint with external URL parameters followed by 3xx responses to off-domain hosts.
- Alert on Location headers in SSO responses that do not match approved internal domains.
- Correlate SSO redirect activity with subsequent authentication attempts or phishing reports from users.
- Hunt for known CVE-2012-0518 exploitation patterns in IDS/IPS signatures if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-0518 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | Broken Link |
| http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html | PatchVendor Advisory |
| http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | Broken Link |
| http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0518 | US Government Resource |
Track CVE-2012-0518 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0518), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.