CVE-2012-1710
Description
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.
In plain language
AI Act nowCVE-2012-1710 is a critical Oracle Fusion Middleware Forms feature flaw that has been used in ransomware, so most businesses using that Oracle software should act now by applying Oracle’s required updates.
CVE-2012-1710 is a remotely triggered Oracle WebCenter Forms Recognition vulnerability in Oracle Fusion Middleware 10.1.3.5 (no authentication required per vulnerability scoring), with confirmed real-world use in ransomware campaigns (CISA KEV), requiring you to apply Oracle’s CPU updates per vendor instructions.
What to do now
- Check whether you run Oracle Fusion Middleware 10.1.3.5 and specifically whether the WebCenter Forms Recognition component is installed/enabled.
- Verify whether your environment has the Oracle CPU/security updates referenced in Oracle’s remediation guidance for this issue (Oracle’s CPU for 2012).
- If you’re affected, apply the vendor updates exactly as Oracle instructs for Fusion Middleware/WebCenter Forms Recognition, then restart affected services as required by the update procedure.
- Confirm the site is reachable only from trusted networks (per your normal hardening rules) and monitor for suspicious activity around the Fusion Middleware/Forms endpoints until patching is complete.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2012-1710 and every CVE in our database. Create a free account — no credit card required.
Create Free Account