cbcvebase.
CVE-2012-3143
published 2012-10-16

CVE-2012-3143: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36…

PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.57%
92.0th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.

Affected

90 ranges· showing 25
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk<= 1.4.2_38
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre<= 1.4.2_38
oraclejre
oraclejre
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk

Detection & IOCsextracted from sources · hover to see the quote

  • ·CVE-2012-3143 is an unspecified JMX vulnerability in Oracle Java SE with no public technical details; affected versions are Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier. Fixed in Oracle JDK 7u9 and 6u37.
  • ·This is a distinct vulnerability from CVE-2012-5089, which is the OpenJDK RMIConnectionImpl insufficient access control checks issue (JMX, 7198296). Both share the JMX attack surface but are separate bugs.
  • ·Fixed in Oracle JDK 7u9 and 6u37 per Red Hat Bugzilla discussion.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.