Oracle WebCenter Forms Recognition contains a flaw related to the Sssplt30.dll ActiveX control. The issue is triggered when an error occurs in the saveLayout() method, which may allow an attacker to overwrite arbitrary files.
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.