← Vulnerability feed

Vulnerability record · CVE-2012-0549 · published 3 May 2012

CVE-2012-0549: Oracle AutoVue Office Desktop API flaw allows remote compromise

Oracle · Supply Chain Products Suite

CVE-2012-0549 is an unspecified vulnerability in the Oracle AutoVue Office component of Oracle Supply Chain Products Suite 20.1.1, tied to the Desktop API. The record gives no root-cause detail, but the flaw affects confidentiality, integrity and availability, so successful exploitation can fully compromise the affected component.

7.5 CVSS 2.0 High EPSS 59% · top 0.9%
7.5CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affect confidentiality, integrity, and availability, related to Desktop API.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 2.0 rates it 7.5 (high) with network reachability and no authentication, and EPSS is at the 99th percentile, though no KEV or confirmed exploitation exists.

What it is

CVE-2012-0549 is an unspecified vulnerability in the Oracle AutoVue Office component of Oracle Supply Chain Products Suite 20.1.1, tied to the Desktop API. The record gives no root-cause detail, but the flaw affects confidentiality, integrity and availability, so successful exploitation can fully compromise the affected component.

Impact

A remote attacker can read and modify data and disrupt availability of the AutoVue Office component, giving broad control over the affected service.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that cannot be confirmed from this record.

Exploitation

No KEV listing and no exploit-tagged references are present, so there is no confirmed in-the-wild exploitation. EPSS is high (0.59045, 99th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Apply the Oracle Critical Patch Update for April 2012 (cpuapr2012-366314) or a later Oracle fix for Supply Chain Products Suite 20.1.1.
  • If AutoVue Office Desktop API is not required, disable or remove the component and restrict access to the service.
  • Segment and firewall the AutoVue/Supply Chain Products Suite hosts so they are not reachable from untrusted networks.
  • Monitor Oracle and downstream vendor advisories (for example Mandriva MDVSA-2013:150) for updated fixes.
  • Review network exposure of the Desktop API and limit it to trusted clients only.

Detection

  • Monitor network traffic to AutoVue Office/Desktop API endpoints for unexpected or malformed requests from untrusted sources.
  • Alert on unusual process or file activity on hosts running Supply Chain Products Suite 20.1.1.
  • Audit authentication and access logs for unauthenticated connections to the AutoVue component.
  • Track for public exploit code or scanning activity targeting Oracle AutoVue Office.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0549 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-21940Oracle supply chain products suite information exposure vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.…EPSS 0.40%7.5CVE-2015-2663Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 a…EPSS 1.8%6.8CVE-2015-0435Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.…EPSS 1.3%6.8CVE-2014-6533Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1 and 6.2 allows remote attackers…EPSS 1.4%6.5CVE-2015-1793OpenSSL X.509 Basic Constraints flaw allows CA role spoofingOpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c mishandle X.509 Basic Constraints cA values while identifying alternative certificate chains in X509_verify…EPSS 62%analysed6.5CVE-2015-2570Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 11.5.10, 12.0, 12.1, and 12.2 allows remote a…EPSS 2.4%5.5CVE-2014-4229Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and …EPSS 1.3%5.5CVE-2013-5897Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.0, 6.1, and …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2012-0549), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.