Vulnerability record · CVE-2012-3152 · published 16 October 2012
CVE-2012-3152: Oracle Fusion Middleware Reports Developer arbitrary file read and upload
Oracle · Fusion Middleware
Oracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality and integrity. The original researcher claims the URLPARAMETER functionality in reports/rwservlet allows reading and uploading arbitrary files, and Oracle has not confirmed that detail. It matters because it can be chained with CVE-2012-3153 to upload a .jsp file and execute code.
Description
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1, CISA KEV listing, EPSS near 1.0, and public exploit references make this a high-risk, actively exploited flaw.
What it is
Oracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality and integrity. The original researcher claims the URLPARAMETER functionality in reports/rwservlet allows reading and uploading arbitrary files, and Oracle has not confirmed that detail. It matters because it can be chained with CVE-2012-3153 to upload a .jsp file and execute code.
Impact
An attacker can read arbitrary files and upload files to the server, exposing sensitive data and enabling code execution when chained with CVE-2012-3153. This gives full compromise of the affected application server.
Attack surface
Reachable over the network through the Reports Developer Report Server component, specifically the reports/rwservlet endpoint per the researcher's claim. The CVSS vector shows no authentication and no user interaction required.
Exploitation
CVE-2012-3152 is listed in CISA KEV with a 2021-11-03 due date, and EPSS is 0.98793 (99.9th percentile); references include Exploit-DB and a YouTube exploit demonstration, indicating public exploitation.
What to do
- Apply the Oracle October 2012 Critical Patch Update or later fixes for Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0.
- If patching is not possible, restrict network access to the Reports Developer rwservlet endpoint to trusted hosts only.
- Disable or remove the Reports Developer/Report Server component if it is not required.
- Monitor and block attempts to upload .jsp or other executable files through the reports/rwservlet interface.
Detection
- Inspect web server and application logs for requests to reports/rwservlet with URLPARAMETER parameters or unusual file paths.
- Alert on file write or upload events in the Reports Developer directories, especially .jsp files.
- Monitor for outbound connections or process execution following Reports Developer requests that could indicate CVE-2012-3153 chaining.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-3152 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3152 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3152), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.