← Vulnerability feed

Vulnerability record · CVE-2012-3153 · published 16 October 2012

CVE-2012-3153: Oracle Fusion Middleware Reports Developer Servlet credential disclosure

Oracle · Fusion Middleware

Oracle Reports Developer in Fusion Middleware 11.1.1.4, 11.1.1.6 and 11.1.2.0 has an unspecified flaw in the Servlet component that affects confidentiality and integrity. Oracle has not confirmed the researcher's claim that the PARSEQUERY function at reports/rwservlet/parsequery exposes database credentials, and the issue is reported to affect earlier versions as well.

6.4 CVSS 2.0 Medium EPSS 98% · top 0.1%
6.4CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.

AV:N/AC:L/Au:N/C:P/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityUnauthenticated network access with partial confidentiality and integrity impact, a very high EPSS score, and public exploit references, though not in KEV.

What it is

Oracle Reports Developer in Fusion Middleware 11.1.1.4, 11.1.1.6 and 11.1.2.0 has an unspecified flaw in the Servlet component that affects confidentiality and integrity. Oracle has not confirmed the researcher's claim that the PARSEQUERY function at reports/rwservlet/parsequery exposes database credentials, and the issue is reported to affect earlier versions as well.

Impact

A remote attacker can read and modify data through the affected component, and the researcher claims database credentials can be obtained. Chained with CVE-2012-3152, it can lead to arbitrary code execution via a .jsp upload.

Attack surface

Reachable over the network through the Reports Developer Servlet, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/Au:N. The claimed vector is the reports/rwservlet/parsequery endpoint.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.9822, 99.9th percentile) and public references include an Exploit-DB entry and researcher blog posts describing exploit release.

What to do

  • Apply the Oracle October 2012 Critical Patch Update or later for Fusion Middleware Reports Developer.
  • If Reports Developer is not needed, disable or remove the component and block external access to /reports/rwservlet.
  • Restrict network access to the Reports servlet to trusted hosts only.
  • Rotate any database credentials that may have been exposed through the Reports servlet.
  • Monitor for and prevent .jsp file uploads to the Reports application to break the CVE-2012-3152 chain.

Detection

  • Alert on requests to /reports/rwservlet/parsequery and other rwservlet endpoints from untrusted sources.
  • Review web and application logs for anomalous Reports Developer servlet requests or unexpected parameters.
  • Monitor for .jsp files written into Reports application directories or web-accessible paths.
  • Hunt for outbound database connections or credential use originating from the Reports server host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3153 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2012-3153), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.