CVE-2012-5076
Oracle Java SE Sandbox Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
Una vulnerabilidad no especificada en el Java Runtime Environment (JRE) en el componente Oracle Java SE v7 Update 7 y versiones anteriores permite a atacantes remotos afectar la confidencialidad, integridad y disponibilidad. Se trata de un problema relacionado con JAX-WS.
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-09-22 CVE Reserved
- 2012-10-16 CVE Published
- 2012-11-13 First Exploit
- 2022-03-28 Exploited in Wild
- 2022-04-18 KEV Due Date
- 2024-08-06 CVE Updated
- 2024-09-11 EPSS Updated
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/51029 | Not Applicable | |
http://secunia.com/advisories/51326 | Not Applicable | |
http://secunia.com/advisories/51390 | Not Applicable | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16641 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24309 | 2013-01-24 | |
https://www.exploit-db.com/exploits/22657 | 2012-11-13 |
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html | 2024-04-26 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html | 2024-04-26 | |
http://rhn.redhat.com/errata/RHSA-2012-1386.html | 2024-04-26 | |
http://rhn.redhat.com/errata/RHSA-2012-1391.html | 2024-04-26 | |
http://rhn.redhat.com/errata/RHSA-2012-1467.html | 2024-04-26 | |
http://security.gentoo.org/glsa/glsa-201406-32.xml | 2024-04-26 | |
https://access.redhat.com/security/cve/CVE-2012-5076 | 2012-11-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=865352 | 2012-11-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update1 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update2 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update3 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update4 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update5 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update6 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update7 |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Desktop Search vendor "Suse" for product "Linux Enterprise Desktop" | 11 Search vendor "Suse" for product "Linux Enterprise Desktop" and version "11" | sp2 |
Affected
|