10

CVE-2012-5076

Warnung
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jre Version 1.7.0 Update -
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update2
Oracle ≫ Jre Version 1.7.0 Update update3
Oracle ≫ Jre Version 1.7.0 Update update4
Oracle ≫ Jre Version 1.7.0 Update update5
Oracle ≫ Jre Version 1.7.0 Update update6
Oracle ≫ Jre Version 1.7.0 Update update7
Suse ≫ Linux Enterprise Desktop Version 11 Update sp2

28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE Sandbox Bypass Vulnerability

Schwachstelle

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.01% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1467.html
Third Party Advisory
http://secunia.com/advisories/51326
Not Applicable
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2012-1391.html
Third Party Advisory
http://secunia.com/advisories/51390
Not Applicable
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
Patch
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2012-1386.html
Third Party Advisory
http://secunia.com/advisories/51029
Not Applicable
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16641
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-5076
US Government Resource