Oracle WebCenter Forms Recognition Sssplt30.ocx ActiveX Control Arbitrary File Creation
| TSL ID | TSL20120424-04 |
| CVE ID(s) | CVE-2012-1710 |
| Severity | Moderate |
| Description | A directory traversal vulnerability exists in Oracle WebCenter Forms Recognition. The vulnerability is due to insufficient validation of parameters used in the "SaveLayout()" method in the ActiveX control Sssplt30.ocx. This can be exploited to write arbitrary files in the context of the currently logged-on user. A remote attacker could possibly exploit this vulnerability to achieve arbitrary code execution by enticing a target user to open a crafted web page. The Vendor, Oracle, has provided an advisory and patches regarding this vulnerability: http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|
| Identifiers | |
| References |
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html |
| Related Threats |