ZeroHour

CVE-2012-3152

KEVlarge

Remote vulnerability in Oracle Fusion Middleware Reports Developer exploited in the wild

CISA: Oracle Fusion Middleware Unspecified Vulnerability

CVSS
EPSS
99%p100
Published
KEV added
AI analysis

CVE-2012-3152 is an unspecified remote vulnerability in the Reports Developer component of Oracle Fusion Middleware that allows attackers to affect the confidentiality and integrity of affected systems. An attacker who can reach the reporting service over the network can send crafted requests to read sensitive data or tamper with information handled by that component; the precise trigger mechanism and authentication requirements are not detailed in available data. Any organization running Oracle Fusion Middleware with the Reports Developer component deployed is potentially affected, with telecoms, ISPs, and hosting providers among the environments observed to be targeted. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and is associated with the Lebanese Cedar APT's intrusions into telecoms, ISPs, and hosting firms worldwide. EPSS rates the 30-day exploitation probability at 98.8% (100th percentile), making prompt patching a high priority.

What to do: Apply vendor-supplied updates to Oracle Fusion Middleware per CISA's required action (apply updates per vendor instructions). Inventory your environment to determine whether the Reports Developer/Oracle Reports component is deployed and whether it is internet-exposed, and restrict network access to it where patching is not immediately possible. Because the flaw has been used in the wild by the Lebanese Cedar APT, especially in telecom, ISP, and hosting environments, also hunt for signs of compromise such as unexpected processes, webshells, or unusual outbound connections.

Affected
Oracle Fusion Middleware (Reports Developer component)
Estimated exposure
largetens of thousands of deployments worldwide (enterprise middleware installed base); exact count unknown — Oracle Fusion Middleware is a widely deployed enterprise middleware suite, and the worldwide telecom/ISP/hosting victim footprint plus typical internet-exposed scan counts for legacy Oracle application-server components imply on the order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

CISA Known Exploited Vulnerability
Affected
Oracle Fusion Middleware
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
Fusion Middleware

In the news