EXPOSURES › CVE-2012-1710
CVE-2012-1710
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.
The Oracle Fusion Middleware WebCenter Forms Recognition component contained an unspecified vulnerability exploitable remotely, affecting confidentiality, integrity, and availability. This failure matters to DIB organizations because it was actively exploited in the wild and linked to ransomware campaigns, indicating a severe, avoidable gap in patch management and threat detection. Organizations must rigorously validate patch levels for middleware components and monitor for ransomware indicators.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, demonstrating a severe, avoidable failure in patch management and threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |