CVE-2016-3542

MEDIUM

Oracle E- Business Suite <12.2.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-3542. PoCs published by SecuriTeam.

AI-analyzed exploit summary This exploit demonstrates an XXE vulnerability in Oracle Knowledge Management, leading to remote code execution by exfiltrating sensitive files (e.g., custom.xml) and decrypting database credentials. The attack involves setting up a malicious XXE server and a gopher listener to extract and decrypt credentials for further exploitation.

Description

Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality and integrity via unknown vectors.

Exploits (1)

exploitdb WORKING POC
by SecuriTeam · textwebappsmultiple
https://www.exploit-db.com/exploits/44041

This exploit demonstrates an XXE vulnerability in Oracle Knowledge Management, leading to remote code execution by exfiltrating sensitive files (e.g., custom.xml) and decrypting database credentials. The attack involves setting up a malicious XXE server and a gopher listener to extract and decrypt credentials for further exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle Knowledge Management versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5
No auth needed
Prerequisites: Access to the target network · Ability to set up a malicious XXE server and gopher listener · Knowledge of the target file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91873
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91787
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036403

Scores

CVSS v3 6.5
EPSS 0.0969
EPSS Percentile 94.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (6)
oracle/knowledge_management 12.1.1
oracle/knowledge_management 12.1.2
oracle/knowledge_management 12.1.3
oracle/knowledge_management 12.2.3
oracle/knowledge_management 12.2.4
oracle/knowledge_management 12.2.5
Published Jul 21, 2016
Tracked Since Feb 18, 2026