← Vulnerability feed

Vulnerability record · CVE-2012-0518 · published 16 October 2012

CVE-2012-0518: Oracle Fusion Middleware SSO open redirect flaw

Oracle · Fusion Middleware

Oracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked as CWE-601. The flaw lets remote attackers influence redirect targets, which matters because SSO redirects are trusted by users and can be abused for phishing or credential theft. The description is thin and does not identify the exact vectors or code path.

4.7 CVSS 3.1 Medium CISA KEV since 28 Mar 2022 EPSS 4.7% · top 8.5% CWE-601 · Open redirect
4.7CVSS 3.1 base score, v2 4.3
4.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with confirmed in-the-wild exploitation, but its CVSS impact is limited to integrity with required user interaction.

What it is

Oracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked as CWE-601. The flaw lets remote attackers influence redirect targets, which matters because SSO redirects are trusted by users and can be abused for phishing or credential theft. The description is thin and does not identify the exact vectors or code path.

Impact

An attacker can redirect a victim to an attacker-controlled site through the trusted SSO endpoint, enabling phishing or credential harvesting. Integrity impact is limited; there is no confidentiality or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the SSO redirect handling with no authentication required, but exploitation requires user interaction (UI:R) since a victim must follow the crafted redirect. The scope is changed (S:C), meaning the redirect can affect resources beyond the vulnerable component.

Exploitation

Listed in CISA KEV since 2022-03-28, indicating known exploitation in the wild, though no ransomware use is documented. EPSS 30-day probability is about 4.7 percent (91st percentile), and the only vendor reference is the October 2012 CPU patch advisory.

What to do

  • Apply the Oracle Critical Patch Update from October 2012 (cpuoct2012-1515893) or a later CPU that supersedes it.
  • If the affected 10.1.4.3.0 SSO component cannot be patched, restrict or disable external redirect handling and validate redirect targets against an allowlist.
  • Place the SSO endpoint behind a reverse proxy or WAF rule that blocks off-domain redirect parameters.
  • Monitor and log SSO redirect responses, alerting on Location headers pointing outside approved domains.
  • Review for exposure of the legacy 10.1.4.3.0 deployment and plan migration off end-of-life Fusion Middleware.

Detection

  • Search web and proxy logs for requests to the SSO redirect endpoint with external URL parameters followed by 3xx responses to off-domain hosts.
  • Alert on Location headers in SSO responses that do not match approved internal domains.
  • Correlate SSO redirect activity with subsequent authentication attempts or phishing reports from users.
  • Hunt for known CVE-2012-0518 exploitation patterns in IDS/IPS signatures if available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-0518 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%9.3CVE-2010-3591Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2012-0518), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.