CVE-2012-0507

Confirmed PUBLISHED

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and...

Oracle · Java SE
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

metasploit java cisa ransomware malware
CVE Published
Jun 07, 2012
Exploitation Reported
Mar 03, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • HPSBUX02784 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=133847939902305&w=2
  • HPSBMU02799 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134254866602253&w=2
  • SSRT100805 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=133365109612558&w=2
  • SUSE-SU-2012:0602 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009...
  • RHSA-2013:1455 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-1455.html
Show 17 more references
  • SUSE-SU-2012:0603 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010...
  • HPSBUX02757 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=133364885411663&w=2
  • DSA-2420 debian.org · Vendor Advisory http://www.debian.org/security/2012/dsa-2420
  • RHSA-2012:0508 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-0508.html
  • SSRT100867 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134254957702612&w=2
  • RHSA-2012:0514 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-0514.html
  • 48692 secunia.com · Third-Party Advisory http://secunia.com/advisories/48692
  • 48589 secunia.com · Third-Party Advisory http://secunia.com/advisories/48589
  • 48950 secunia.com · Third-Party Advisory http://secunia.com/advisories/48950
  • 48948 secunia.com · Third-Party Advisory http://secunia.com/advisories/48948
  • 48915 secunia.com · Third-Party Advisory http://secunia.com/advisories/48915
  • 52161 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/52161
  • oracle.com/technetwork/topics/security/javacpufeb2012-3... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/javacpufeb2012-3663...
  • krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-... krebsonsecurity.com · CVE Record http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploi...
  • weblog.ikvm.net/PermaLink.aspx weblog.ikvm.net · CVE Record http://weblog.ikvm.net/PermaLink.aspx?guid=cd48169a-9405-4f63-9087-79...
  • blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-cas... blogs.technet.com · CVE Record http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-cas...
  • bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=788994

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.