EXPOSURES › CVE-2012-3152
CVE-2012-3152
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity.
This unpatched vulnerability in Oracle Fusion Middleware enables remote attackers to affect system confidentiality and integrity, representing a significant compliance risk for DIB organizations relying on Oracle middleware. The failure highlights the danger of relying on vendors with high volumes of critical unauthenticated RCE vulnerabilities and slow patch cycles, requiring strict inventory management and accelerated patching schedules.
Shame score — The vulnerability remains unpatched and is actively exploited in the wild (KEV), demonstrating negligent vendor patching cycles and avoidable exposure to remote attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.
"Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |