CVE-2012-1723
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 94% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-284
מוצרים מושפעים
oracle: jdk; oracle: jre; redhat: icedtea6; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux workstation
קישורים
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html Vendor Advisory
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html Mailing List
- http://marc.info/?l=bugtraq&m=134496371727681&w=2 Mailing List
- http://rhn.redhat.com/errata/RHSA-2012-0734.html Third Party Advisory
- http://secunia.com/advisories/51080 Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21615246 Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:095 Broken Link
- http://www.securityfocus.com/bid/53960 Broken LinkThird Party AdvisoryVDB Entry