CVE-2012-1543
published 2013-02-02CVE-2012-1543: Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and…
PriorityP342high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
4.40%
90.3th percentile
Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an invalid type cast in the JSObject class.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | javafx | <= 2.2.4 | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
bugzilla·2012-11-30·CVSS 5.5
CVE-2012-5603 [MEDIUM] CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
Lukas Zapletal of Red Hat reports:
Regular user (somebody with username and password) and a consumer UUID of any
system can download the consumer certificate and consume content or modify
data without permission to do that.
Discussion:
Acknowledgements:
This issue was discovered by Lukas Zapletal of Red Hat.
---
This issue has been addressed in following products:
CloudForms for RHEL 6
CloudForms Tools for RHEL 5
Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
---
The Red Hat Security Response Team has rated this
Bugzilla
CVE-2012-5605 CloudForms grinder: /var/lib/pulp/cache/grinder directory is world-writeable
bugzilla·2012-11-30·CVSS 2.1
CVE-2012-5605 [LOW] CVE-2012-5605 CloudForms grinder: /var/lib/pulp/cache/grinder directory is world-writeable
CVE-2012-5605 CloudForms grinder: /var/lib/pulp/cache/grinder directory is world-writeable
James Labocki of Red Hat reports:
The /var/lib/pulp/cache/grinder directory is world-writeable
Discussion:
Acknowledgements:
This issue was discovered by James Labocki of Red Hat.
---
This issue has been addressed in following products:
CloudForms for RHEL 6
CloudForms Tools for RHEL 5
Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html
---
Statement:
Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.r
http://marc.info/?l=bugtraq&m=136733161405818&w=2http://www.kb.cert.org/vuls/id/858729http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttp://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1026https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16673http://marc.info/?l=bugtraq&m=136733161405818&w=2http://www.kb.cert.org/vuls/id/858729http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttp://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1026https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16673
2013-02-02
Published