EXPOSURES › CVE-2012-0518
CVE-2012-0518
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity.
This vulnerability in Oracle Fusion Middleware's Single Sign-On component allowed remote attackers to affect system integrity, highlighting the risk of unpatched legacy systems. DIB organizations must ensure all Oracle middleware is patched and monitored, as this CVE is actively exploited in the wild. Failure to patch such components can lead to data breaches or ransomware entry.
Shame score — The vulnerability was actively exploited in the wild (KEV) and affected a widely deployed enterprise product, indicating a significant compliance and security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |