Skip to content
COOEY

FAIL › dossier

Fusion Middleware

PRODUCT

· dossier confidence 20%

Oracle Fusion Middleware exhibits a high frequency of critical unauthenticated RCE vulnerabilities, with a record July 2026 CPU addressing 1,449 fixes including ten CVSS 10.0 flaws. The company has shifted to monthly security cycles due to AI-driven discovery outpacing quarterly remediation.

PROFILE
CategoryEnterprise Software VendorWhat they doOracle Corporation provides enterprise information technology frameworks including cloud software as a service and enterprise resource planning solutions. Websitehttps://www.oracle.com ↗
SECURITY POSTURE

High volume of critical unauthenticated RCE vulnerabilities in Fusion Middleware products, with a shift to monthly patch cycles due to AI-driven discovery outpacing quarterly remediation.

Notable failures
  • CVE-2025-61757: Unauthenticated takeover via Identity Manager
  • CVE-2021-35587: Unauthenticated takeover of Access Manager
  • CVE-2020-2551: Unauthenticated compromise of WebLogic Core Components
  • CVE-2012-1710: Remote compromise of WebCenter Forms Recognition
  • CVE-2012-0518: Remote integrity impact in Single Sign-On
  • CVE-2012-3152: Remote confidentiality/integrity impact in Reports Developer
Patterns: Repeated unauthenticated RCEs in Fusion Middleware; High volume of critical vulnerabilities in quarterly CPU; AI-driven vulnerability discovery outpacing remediation
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2022-05-25 CVE-2012-1710 critical Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.
2025-11-21 CVE-2025-61757 high Oracle Fusion Middleware exposed to unauthenticated takeover via Identity Manager
2023-11-16 CVE-2020-2551 high Oracle Fusion Middleware WLS Core Components RCE vulnerability
2022-11-28 CVE-2021-35587 high Oracle Fusion Middleware exposed to unauthenticated RCE via HTTP
2021-11-03 CVE-2012-3152 high Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity.
2022-03-28 CVE-2012-0518 high Oracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity.
2020-05-01 CVE-2020-10683 critical CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti
2012-05-03 CVE-2012-1710 critical CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in
Open questions: Oracle's patch management process for Fusion Middleware components · Current security posture improvements post-2025 vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:43:25.577925+00:00