CVE-2012-0106
https://notcve.org/view.php?id=CVE-2012-0106
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web. Una vulnerabilidad no especificada en el componente "Oracle Imaging and Process Management" en Oracle Fusion Middleware v10.1.3.6.0 permite a usuarios remotos autenticados afectar la confidencialidad y la integridad a través de vectores desconocidos relacionados con la Web. • http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html •
CVE-2012-3152 – Oracle Fusion Middleware Unspecified Vulnerability
https://notcve.org/view.php?id=CVE-2012-3152
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file. Vulnerabilidad no especificada en el componente de Oracle Reports Developer de Oracle Fusion Middleware v11.1.1.4, v11.1.1.6 y v11.1.2.0 permite a atacantes remotos afectar a la confidencialidad y la integridad a través de vectores desconocidos relacionados con Report Server Component. • https://www.exploit-db.com/exploits/31253 https://www.exploit-db.com/exploits/31737 http://blog.netinfiltration.com/2013/11/03/oracle-reports-cve-2012-3152-and-cve-2012-3153 http://blog.netinfiltration.com/2014/01/19/upcoming-exploit-release-oracle-forms-and-reports-11g http://seclists.org/fulldisclosure/2014/Jan/186 http://www.exploit-db.com/exploits/31253 http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuoct2012-151 •
CVE-2012-0090
https://notcve.org/view.php?id=CVE-2012-0090
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0092. Vulnerabilidad no especificada en el componente Oracle Imaging y Process Management en Oracle Fusion Middleware 10.1.3.6.0 permite a usuarios remotos autenticados afectar la integridad a través de vectores desconocidos relacionado con Web, una vulnerabilidad diferente a CVE-2012-0092. • http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html •
CVE-2012-0107
https://notcve.org/view.php?id=CVE-2012-0107
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect availability via unknown vectors related to Web. Vulnerabilidad no especificada en el componente Oracle Imaging y Process Management en Oracle Fusion Middleware v10.1.3.6.0 permite a atacantes remotos afectar la disponibilidad mediante vectores relacionados con Web. • http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html •
CVE-2012-0092
https://notcve.org/view.php?id=CVE-2012-0092
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0090. Vulnerabilidad no especificada en el componente Oracle Imaging y Process Management en Oracle Fusion Middleware 10.1.3.6.0 permite a usuarios remotos autenticados afectar la integridad a través de vectores desconocidos relacionado con Web, una vulnerabilidad diferente a CVE-2012-0090. • http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html •