Unspecified remote flaw in Oracle WebCenter Forms Recognition Designer (CVE-2012-1710)
CISA: Oracle Fusion Middleware Unspecified Vulnerability
CVE-2012-1710 is an unspecified vulnerability in the Designer component of Oracle WebCenter Forms Recognition, a forms-processing product within Oracle Fusion Middleware, addressed by Oracle in its April 2012 Critical Patch Update. It is triggered remotely through the Designer component, but the exact attack vectors were never publicly detailed and no public proof-of-concept is known. A successful attacker can affect confidentiality, integrity, and availability — i.e., read, alter, or disrupt data handled by Forms Recognition — and CISA notes documented ransomware use. Organizations running Oracle WebCenter Forms Recognition 10.1.3 or 11.1.1 (per Oracle's April 2012 advisory) are in scope; CISA's listing covers affected Oracle Fusion Middleware without a narrower published range. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2022-05-25, and EPSS currently puts the 30-day exploitation probability at 11.5% (96th percentile).
What to do: Apply the Forms Recognition fix from Oracle's April 2012 Critical Patch Update, or move to a later patched release, per Oracle's instructions — this is the required action in CISA's KEV catalog. Inventory any internet-exposed Forms Recognition/Designer instances and monitor them for ransomware activity, since real-world exploitation is documented. As an interim measure, restrict network access to Forms Recognition hosts from untrusted networks.
| Oracle WebCenter Forms Recognition (component of Oracle Fusion Middleware) | 10.1.3 and 11.1.1 (per Oracle's April 2012 Critical Patch Update); no narrower version range specified in the CISA listing |
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
No ingested article mentions this CVE yet.