Skip to content
COOEY

EXPOSURES › CVE-2012-0518

CVE-2012-0518

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-0518 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Oracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity.

This vulnerability in Oracle Fusion Middleware's Single Sign-On component allowed remote attackers to affect system integrity, highlighting the risk of unpatched legacy systems. DIB organizations must ensure all Oracle middleware is patched and monitored, as this CVE is actively exploited in the wild. Failure to patch such components can lead to data breaches or ransomware entry.

Shame score — The vulnerability was actively exploited in the wild (KEV) and affected a widely deployed enterprise product, indicating a significant compliance and security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized