CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2012-1710

CVSS 9.8v3.1pub. 2012-05-03upd. 2026-08-04

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Oracle Fusion Middleware

    APP
    Oracle
    10.1.3.5

CISA KEV — detailsi

Vendori
Oracle
Producti
Fusion Middleware
Added to KEVi
May 25, 2022
Remediation deadline (US Federal)i
June 15, 2022(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 15 czerwca 2022
CWE
References

Related vulnerabilities

CVE-2012-3152CRITICAL9.1⚠ KEVPL ✓same product

Oracle Reports Developer – odczyt i upload plików umożliwiający RCE

CVE-2026-60376CRITICAL9.8PL ✓same product

Przejęcie kontroli nad Oracle Service Delivery Platform przez sieć

CVE-2026-60374CRITICAL9.8PL ✓same product

Krytyczne obejście uwierzytelnienia w Oracle Service Delivery Platform

CVE-2026-60375CRITICAL9.8PL ✓same product

Krytyczna podatność w Oracle Service Delivery Platform – przejęcie systemu

CVE-2026-60377CRITICAL9.9PL ✓same product

Krytyczna podatność w Oracle Service Delivery Platform – komponent Messaging Enabler