Oracle WebCenter Forms Recognition ActiveX Control Arbitrary File Creation
| TSL ID | TSL20120425-01 |
| CVE ID(s) | CVE-2012-1709 |
| Severity | Moderate |
| Description | A directory traversal vulnerability exists in Oracle WebCenter Forms Recognition. The vulnerability is due to insufficient validation of parameters used in the Save() method in the ActiveX control CroProj.dll. This can be exploited to write arbitrary files in the context of the currently logged-on user. A remote attacker could possibly exploit this vulnerability to achieve arbitrary code execution by enticing a target user to open a crafted web page. The Vendor, Oracle, has provided an advisory and patches regarding this vulnerability: http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|
| Identifiers | |
| References |
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html |
| Related Threats |