← Vulnerability feed

Vulnerability record · CVE-2012-3152 · published 16 October 2012

CVE-2012-3152: Oracle Fusion Middleware Reports Developer arbitrary file read and upload

Oracle · Fusion Middleware

Oracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality and integrity. The original researcher claims the URLPARAMETER functionality in reports/rwservlet allows reading and uploading arbitrary files, and Oracle has not confirmed that detail. It matters because it can be chained with CVE-2012-3153 to upload a .jsp file and execute code.

9.1 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 99% · top 0.1%
9.1CVSS 3.1 base score, v2 6.4
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
23References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityCVSS 9.1, CISA KEV listing, EPSS near 1.0, and public exploit references make this a high-risk, actively exploited flaw.

What it is

Oracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality and integrity. The original researcher claims the URLPARAMETER functionality in reports/rwservlet allows reading and uploading arbitrary files, and Oracle has not confirmed that detail. It matters because it can be chained with CVE-2012-3153 to upload a .jsp file and execute code.

Impact

An attacker can read arbitrary files and upload files to the server, exposing sensitive data and enabling code execution when chained with CVE-2012-3153. This gives full compromise of the affected application server.

Attack surface

Reachable over the network through the Reports Developer Report Server component, specifically the reports/rwservlet endpoint per the researcher's claim. The CVSS vector shows no authentication and no user interaction required.

Exploitation

CVE-2012-3152 is listed in CISA KEV with a 2021-11-03 due date, and EPSS is 0.98793 (99.9th percentile); references include Exploit-DB and a YouTube exploit demonstration, indicating public exploitation.

What to do

  • Apply the Oracle October 2012 Critical Patch Update or later fixes for Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0.
  • If patching is not possible, restrict network access to the Reports Developer rwservlet endpoint to trusted hosts only.
  • Disable or remove the Reports Developer/Report Server component if it is not required.
  • Monitor and block attempts to upload .jsp or other executable files through the reports/rwservlet interface.

Detection

  • Inspect web server and application logs for requests to reports/rwservlet with URLPARAMETER parameters or unusual file paths.
  • Alert on file write or upload events in the Reports Developer directories, especially .jsp files.
  • Monitor for outbound connections or process execution following Reports Developer requests that could indicate CVE-2012-3153 chaining.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-3152 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.netinfiltration.com/2013/11/03/oracle-reports-cve-2012-3152-and-cve-2012-3153/ Broken Link
http://blog.netinfiltration.com/2014/01/19/upcoming-exploit-release-oracle-forms-and-reports-11g/ Broken Link
http://seclists.org/fulldisclosure/2014/Jan/186 Mailing ListThird Party Advisory
http://www.exploit-db.com/exploits/31253 ExploitThird Party AdvisoryVDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Broken Link
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html PatchVendor Advisory
http://www.osvdb.org/86394 Broken Link
http://www.osvdb.org/86395 Broken Link
http://www.securityfocus.com/bid/55955 Broken LinkThird Party AdvisoryVDB Entry
http://www.youtube.com/watch?v=NinvMDOj7sM Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/79295 Third Party AdvisoryVDB Entry
http://blog.netinfiltration.com/2013/11/03/oracle-reports-cve-2012-3152-and-cve-2012-3153/ Broken Link
http://blog.netinfiltration.com/2014/01/19/upcoming-exploit-release-oracle-forms-and-reports-11g/ Broken Link
http://seclists.org/fulldisclosure/2014/Jan/186 Mailing ListThird Party Advisory
http://www.exploit-db.com/exploits/31253 ExploitThird Party AdvisoryVDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Broken Link
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html PatchVendor Advisory
http://www.osvdb.org/86394 Broken Link
http://www.osvdb.org/86395 Broken Link
http://www.securityfocus.com/bid/55955 Broken LinkThird Party AdvisoryVDB Entry
http://www.youtube.com/watch?v=NinvMDOj7sM Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/79295 Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-3152 US Government Resource

Track CVE-2012-3152 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%9.3CVE-2010-3591Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2012-3152), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.