CVE-2012-3186
published 2012-10-17CVE-2012-3186: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and…
PriorityP431medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EXPLOIT
EPSS
4.21%
89.9th percentile
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3185.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fjq7-xhq9-6w65: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2012-3183 [MEDIUM] GHSA-fjq7-xhq9-6w65: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3185 and CVE-2012-3186.
GHSA
GHSA-p5qx-4pvm-qg6w: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2012-3186 [MEDIUM] GHSA-p5qx-4pvm-qg6w: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3185.
GHSA
GHSA-wch5-v2f5-whhh: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2012-3185 [MEDIUM] GHSA-wch5-v2f5-whhh: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3186.
No detection rules found.
Exploit-DB
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
exploitdb·2019-12-06·CVSS 7.1
CVE-2019-15627 [HIGH] Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
---
# Exploit Title: Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
# Exploit Author : Peter Lapp
# Exploit Date: 2019-12-05
# Vendor Homepage : https://www.trendmicro.com/en_us/business.html
# Link Software : https://help.deepsecurity.trendmicro.com/software.html?regs=NABU&prodid=1716
# Tested on OS: v11.0.582 and v10.0.3186 on Windows Server 2012 R2, 2008R2, and 7 Enterprise.
# CVE: 2019-15627
# CVE-2019-15627 - Trend Micro Deep Security Agent Local File Overwrite Exploit by Peter Lapp (lappsec)
# This script uses the symboliclink-testing-tools project, written by James Forshaw ( https://github.com/googleprojectzero/symboliclink-testing-tools )
# The vulnerability allows an unprivileged local attacker to del
Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
exploitdb·2012-10-17·CVSS 4.9
CVE-2012-3186 [MEDIUM] Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
---
SEC Consult Vulnerability Lab Security Advisory
title: Multiple vulnerabilities in Oracle WebCenter Sites
product: Oracle WebCenter Sites (former FatWire Content Server)
vulnerable version: 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1,
7.6.2, 11.1.1.6.0
fixed version: Patch information see sections below
CVE: CVE-2012-3183 (S0183794)
CVE-2012-3184 (S0183815)
CVE-2012-3185 (S0183827)
CVE-2012-3186 (S0183836)
impact: High
homepage: http://www.oracle.com/us/corporate/acquisitions/fatwire/index.html
found: 21.05.2012
by: F. Lukavsky
SEC Consult Vulnerability Lab
https://www.sec-consult.com
Vendor description:
FatWire Content Server is a predecessor product of Oracle WebCenter Sites.
FatWire Content Server
No writeups or analysis indexed.
2012-10-17
Published