← Vulnerability feed

Vulnerability record · CVE-2012-1710 · published 3 May 2012

CVE-2012-1710: Oracle Fusion Middleware WebCenter Forms Recognition unspecified flaw

Oracle · Fusion Middleware

CVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable through unknown vectors related to Designer. It is distinct from CVE-2012-1709. Because the flaw is unspecified, the exact root cause is not documented, but the record rates it critical and CISA lists it as exploited.

9.8 CVSS 3.1 Critical CISA KEV since 25 May 2022 Known ransomware use EPSS 7.8% · top 5.5%
9.8CVSS 3.1 base score, v2 7.5
7.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
4 Aug 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network, unauthenticated, no-interaction access plus CISA KEV listing and known ransomware use make this an urgent remediation target despite the thin technical description.

What it is

CVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable through unknown vectors related to Designer. It is distinct from CVE-2012-1709. Because the flaw is unspecified, the exact root cause is not documented, but the record rates it critical and CISA lists it as exploited.

Impact

A successful attack can affect confidentiality, integrity and availability, meaning an unauthenticated remote attacker could read, alter or disrupt data handled by the affected component. The full scope of what is exposed is not described in the record.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction, so the component is exposed to remote unauthenticated requests. The description gives no further detail on the specific interface or protocol involved.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-05-25 with a due date of 2022-06-15 and flags known ransomware campaign use. EPSS puts 30-day exploitation probability at about 11.5 percent (95.8th percentile).

What to do

  • Apply the Oracle Critical Patch Update referenced in the vendor advisory (cpuapr2012-366314) or a later supported patch level.
  • If WebCenter Forms Recognition is not required, disable or remove the component and restrict network access to it.
  • Place the affected Fusion Middleware deployment behind access controls so only trusted networks and users can reach it.
  • Monitor CISA KEV guidance and vendor advisories for updated remediation instructions, since the vulnerability details are unspecified.

Detection

  • Review web and application logs for anomalous requests to WebCenter Forms Recognition or Designer endpoints from unexpected sources.
  • Alert on exploitation attempts or post-exploitation behavior tied to known ransomware activity, given the KEV ransomware flag.
  • Inventory internet-facing or broadly reachable Fusion Middleware 10.1.3.5 instances and confirm patch status against the vendor advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-1710 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Oracle Fusion Middleware Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%9.3CVE-2010-3591Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2012-1710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.