CVE-2012-0518

MEDIUM KEV

Oracle Application Server <10.1.4.3.0 - Open Redirect

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2012-0518 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022.

Description

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

References (3)

Core 3
Core References
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150

Scores

CVSS v3 4.7
EPSS 0.2090
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2022-03-28
VulnCheck KEV 2013-05-17
InTheWild.io 2022-03-28
ENISA EUVD EUVD-2012-0550
CWE
CWE-601
Status published
Products (1)
oracle/fusion_middleware 10.1.4.3
Published Oct 16, 2012
KEV Added Mar 28, 2022
Tracked Since Feb 18, 2026