CVE-2012-5076

Confirmed PUBLISHED

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to...

Oracle · Java SE
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

cisa metasploit java
CVE Published
Oct 16, 2012
Exploitation Reported
Mar 28, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • SUSE-SU-2012:1398 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016...
  • GLSA-201406-32 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201406-32.xml
  • RHSA-2012:1386 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-1386.html
  • RHSA-2012:1391 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-1391.html
  • RHSA-2012:1467 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-1467.html
Show 5 more references
  • 51029 secunia.com · Third-Party Advisory http://secunia.com/advisories/51029
  • 51390 secunia.com · Third-Party Advisory http://secunia.com/advisories/51390
  • 51326 secunia.com · Third-Party Advisory http://secunia.com/advisories/51326
  • oval:org.mitre.oval:def:16641 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • oracle.com/technetwork/topics/security/javacpuoct2012-1... oracle.com · CVE Record http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.