Vulnerability record · CVE-2012-3153 · published 16 October 2012
CVE-2012-3153: Oracle Fusion Middleware Reports Developer Servlet credential disclosure
Oracle · Fusion Middleware
Oracle Reports Developer in Fusion Middleware 11.1.1.4, 11.1.1.6 and 11.1.2.0 has an unspecified flaw in the Servlet component that affects confidentiality and integrity. Oracle has not confirmed the researcher's claim that the PARSEQUERY function at reports/rwservlet/parsequery exposes database credentials, and the issue is reported to affect earlier versions as well.
Description
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.
AV:N/AC:L/Au:N/C:P/I:P/A:N
Automated analysis
high priorityUnauthenticated network access with partial confidentiality and integrity impact, a very high EPSS score, and public exploit references, though not in KEV.
What it is
Oracle Reports Developer in Fusion Middleware 11.1.1.4, 11.1.1.6 and 11.1.2.0 has an unspecified flaw in the Servlet component that affects confidentiality and integrity. Oracle has not confirmed the researcher's claim that the PARSEQUERY function at reports/rwservlet/parsequery exposes database credentials, and the issue is reported to affect earlier versions as well.
Impact
A remote attacker can read and modify data through the affected component, and the researcher claims database credentials can be obtained. Chained with CVE-2012-3152, it can lead to arbitrary code execution via a .jsp upload.
Attack surface
Reachable over the network through the Reports Developer Servlet, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/Au:N. The claimed vector is the reports/rwservlet/parsequery endpoint.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.9822, 99.9th percentile) and public references include an Exploit-DB entry and researcher blog posts describing exploit release.
What to do
- Apply the Oracle October 2012 Critical Patch Update or later for Fusion Middleware Reports Developer.
- If Reports Developer is not needed, disable or remove the component and block external access to /reports/rwservlet.
- Restrict network access to the Reports servlet to trusted hosts only.
- Rotate any database credentials that may have been exposed through the Reports servlet.
- Monitor for and prevent .jsp file uploads to the Reports application to break the CVE-2012-3152 chain.
Detection
- Alert on requests to /reports/rwservlet/parsequery and other rwservlet endpoints from untrusted sources.
- Review web and application logs for anomalous Reports Developer servlet requests or unexpected parameters.
- Monitor for .jsp files written into Reports application directories or web-accessible paths.
- Hunt for outbound database connections or credential use originating from the Reports server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3153 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3153), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.