CVE Tools

Description

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.

In plain language

AI Act now

CVE-2012-1710 is a critical Oracle Fusion Middleware Forms feature flaw that has been used in ransomware, so most businesses using that Oracle software should act now by applying Oracle’s required updates.

Executive summary

CVE-2012-1710 is a remotely triggered Oracle WebCenter Forms Recognition vulnerability in Oracle Fusion Middleware 10.1.3.5 (no authentication required per vulnerability scoring), with confirmed real-world use in ransomware campaigns (CISA KEV), requiring you to apply Oracle’s CPU updates per vendor instructions.

If affected, business impact
Ransomware riskFull service disruptionData theft riskSystem compromise risk

What to do now

  1. Check whether you run Oracle Fusion Middleware 10.1.3.5 and specifically whether the WebCenter Forms Recognition component is installed/enabled.
  2. Verify whether your environment has the Oracle CPU/security updates referenced in Oracle’s remediation guidance for this issue (Oracle’s CPU for 2012).
  3. If you’re affected, apply the vendor updates exactly as Oracle instructs for Fusion Middleware/WebCenter Forms Recognition, then restart affected services as required by the update procedure.
  4. Confirm the site is reachable only from trusted networks (per your normal hardening rules) and monitor for suspicious activity around the Fusion Middleware/Forms endpoints until patching is complete.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 25, 2022
Remediation due:Jun 15, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

Official Patch Available

References

and 7 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2012-1710 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store