LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2012-1710: Oracle Fusion Middleware Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2012-1710 to its Known Exploited Vulnerabilities catalog on May 25, 2022, with a federal patch deadline of Jun 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown…

CVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware. Remote attackers can affect confidentiality, integrity, and availability through unknown vectors related to Designer. It matters because the flaw can be reached remotely, has been associated with ransomware activity, and sits in middleware that often processes or sits near sensitive business data.

Public technical detail is limited. Confirm exact impact, fixed releases, and configuration notes against the vendor advisory before acting.

How it works

The CWE class is not specified in the available record. What is known is that the issue resides in the Oracle WebCenter Forms Recognition component and is reachable via unknown vectors tied to the Designer functionality. An attacker who can reach the affected service remotely may be able to compromise confidentiality, integrity, and availability of the component or the data it handles.

Because the vectors are listed as unknown, defenders should treat any network-accessible Designer-related interface or service as potentially in scope until the vendor advisory clarifies the attack surface. Do not assume authentication is required or that only certain protocols are involved; verify those points in the official guidance.

Am I affected? How to find it in your systems

Oracle Fusion Middleware, and specifically the WebCenter Forms Recognition component, typically appears in enterprise document-capture, forms-processing, and related middleware deployments. It may run on application servers or dedicated hosts inside data centers or cloud VPCs.

How to remediate

Patch first. Apply the updates supplied by Oracle for this CVE exactly as described in the vendor advisory and in line with the CISA-required action to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to data theft or encryption. If you have evidence of compromise or suspect exposure, follow your incident-response plan, preserve logs, and assess what data the affected middleware could access. You can also run a free exposure scan of your email addresses against known breach data to see whether credentials or identities tied to your environment have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Fusion Middleware
Added to CISA KEVMay 25, 2022
Federal patch deadlineJun 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities