CVE-2012-1710
Oracle WebCenter Forms Recognition in Oracle Fusion Middleware 10.1.3.5 contains a critical flaw that lets remote attackers compromise confidentiality, integrity, and availability. The vulnerability is unspecified but can be exploited without authentication or user interaction. Oracle has released an update to fix the issue.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Oracle Fusion Middleware 10.1.3.5 that run the WebCenter Forms Recognition component.
Real-world impact
An attacker could read, alter, or delete data and disrupt the availability of the affected services.
Why this severity
The CVSS score of 9.8 reflects a critical vulnerability that requires no authentication, no user interaction, and grants full control over confidentiality, integrity, and availability.
What to do about it
- 01Apply updates per vendor instructions.
CISA KEV required action
Timeline
- May 3, 2012 · May 3, 2012PublishedDisclosed and added to the National Vulnerability Database.
- May 25, 2022 · May 25, 2022Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jun 15, 2022 · Jun 15, 2022CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- mandriva.com/security/advisoriesbroken link
- oracle.com/technetwork/topics/security…patchvendor advisory
- securitytracker.com/idbroken linkthird party advisoryvdb entry
- cisa.gov/known-exploited-vulnerabili…us government resource