CVE-2012-3136
published 2012-08-30CVE-2012-3136: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.95%
89.3th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenJDK: beans ClassFinder insufficient permission checks (beans, 7162476)
vendor_redhat·2012-08-30·CVSS 10.0
CVE-2012-1682 [CRITICAL] OpenJDK: beans ClassFinder insufficient permission checks (beans, 7162476)
OpenJDK: beans ClassFinder insufficient permission checks (beans, 7162476)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Package: java-1.6.0-sun (Red Hat
Red Hat
OpenJDK: beans MethodElementHandler insufficient permission checks (beans, 7194567)
vendor_redhat·2012-08-30·CVSS 10.0
CVE-2012-3136 [CRITICAL] OpenJDK: beans MethodElementHandler insufficient permission checks (beans, 7194567)
OpenJDK: beans MethodElementHandler insufficient permission checks (beans, 7194567)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Package: java-1.6.0-ibm
GHSA
GHSA-3cq6-v88g-8x73: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect c
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-1682 [CRITICAL] GHSA-3cq6-v88g-8x73: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect c
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."
GHSA
GHSA-5jvp-8v86-8h9w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect c
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2012-3136 [CRITICAL] GHSA-5jvp-8v86-8h9w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect c
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.
VulnCheck
Oracle Java SE 7 Update 6 and earlier Java Runtime Environment (JRE) Vulnerability
vulncheck·2012·CVSS 10.0
CVE-2012-1682 [CRITICAL] Oracle Java SE 7 Update 6 and earlier Java Runtime Environment (JRE) Vulnerability
Oracle Java SE 7 Update 6 and earlier Java Runtime Environment (JRE) Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."
Affected: Oracle jdk
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/adobe-flash-player-0-day-and-hackingteams-remote-control-system/64215
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://marc.info/?l=bugtraq&m=135109152819176&w=2http://rhn.redhat.com/errata/RHSA-2012-1225.htmlhttp://secunia.com/advisories/51044http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://marc.info/?l=bugtraq&m=135109152819176&w=2http://rhn.redhat.com/errata/RHSA-2012-1225.htmlhttp://secunia.com/advisories/51044http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html
2012-08-30
Published