LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2012-0518: Oracle Fusion Middleware Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
CVSS 4.7 · Medium⚠ Actively exploited (CISA KEV)
4.7
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2012-0518 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

CVE-2012-0518 is an unspecified vulnerability in the Oracle Application Server Single Sign-On component of Oracle Fusion Middleware. It is associated with CWE-601 and allows remote attackers to affect integrity through unknown vectors. For organizations running this middleware stack, integrity impact on a single sign-on path can undermine trust in authentication flows and related redirects, so teams should treat it as a priority to inventory and remediate according to the vendor advisory.

Public detail on exact mechanics is limited. Confirm affected releases, fixed versions, and any configuration prerequisites directly against Oracle’s advisory before acting.

How it works

CWE-601 describes open redirect weaknesses: an application accepts an untrusted value that influences where a user or browser is sent after a step in a flow, without sufficiently restricting the destination. In a single sign-on context, that often means a parameter used after login, logout, or error handling can be manipulated so the client is directed somewhere the attacker chooses.

An attacker who can influence that destination may craft links or requests that look legitimate because they start on the real SSO host, then land the victim on a malicious site. That can support phishing, session fixation-style tricks, or other integrity attacks against users who trust the SSO domain. The CISA summary for this CVE states only that remote attackers can affect integrity via unknown vectors in the Oracle Application Server Single Sign-On component; it does not publish exploit steps or payloads. Do not assume specific parameter names or request shapes—validate behavior and fixes only from the vendor advisory.

Am I affected? How to find it in your systems

Oracle Fusion Middleware, including Application Server Single Sign-On components, typically appears in enterprise identity, portal, and application integration environments—often on dedicated middleware hosts, reverse-proxy front ends, or shared SSO infrastructure used by multiple internal and partner applications.

How to remediate

Patch first. Apply the updates Oracle specifies for this vulnerability in Fusion Middleware / Application Server Single Sign-On, following the vendor’s installation and restart order. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities can lead to account compromise or follow-on breaches even when the direct impact is described as integrity. Known ransomware use is not documented for this CVE. If you suspect misuse of your SSO endpoints, rotate credentials and session material for affected users, review authentication logs for suspicious redirects or sessions, and follow your incident response process. You can also run a free exposure scan of your email addresses against known breach data to see whether related identities already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Fusion Middleware
WeaknessCWE-601
CVSS base score4.7 (Medium)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
PublishedOct 16, 2012
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities