peter bassill · operator
$ cve CVE-2012-0507 JSON

CVE-2012-0507 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 98.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.11% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-843
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2012-06-07
Last modified2026-08-14

CISA KEV

NameOracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productOracle / Java SE
Ransomware useknown

Affected (7)

VendorProduct
debiandebian linux
oraclejre
sunjre
suselinux enterprise desktop
suselinux enterprise java
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

SourceTitleDate
exploit-dbJava - AtomicReferenceArray Type Violation (Metasploit)2012-03-30

References

→ the Explorer  ·  watch your stack  ·  NVD