CVE-2012-3143
published 2012-10-16CVE-2012-3143: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.57%
92.0th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | <= 1.5.0 | — |
| oracle | jdk | <= 1.4.2_38 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.5.0 | — |
| oracle | jre | <= 1.4.2_38 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·CVE-2012-3143 is an unspecified JMX vulnerability in Oracle Java SE with no public technical details; affected versions are Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier. Fixed in Oracle JDK 7u9 and 6u37. ↗
- ·This is a distinct vulnerability from CVE-2012-5089, which is the OpenJDK RMIConnectionImpl insufficient access control checks issue (JMX, 7198296). Both share the JMX attack surface but are separate bugs. ↗
- ·Fixed in Oracle JDK 7u9 and 6u37 per Red Hat Bugzilla discussion. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpr7-2rf2-926r: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2012-5089 [CRITICAL] GHSA-rpr7-2rf2-926r: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-3143.
GHSA
GHSA-pqv3-87c3-h9cw: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5
ghsa_unreviewed·2022-05-14·CVSS 7.6
CVE-2012-3143 [HIGH] GHSA-pqv3-87c3-h9cw: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2012-10-26·CVSS 10.0
CVE-2012-1531 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Several information disclosure vulnerabilities were discovered in the
OpenJDK JRE. (CVE-2012-3216, CVE-2012-5069, CVE-2012-5072, CVE-2012-5075,
CVE-2012-5077, CVE-2012-5085)
Vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure and data integrity. (CVE-2012-4416, CVE-2012-5071)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to cause a denial of service. (CVE-2012-1531, CVE-2012-1532, CVE-2012-1533,
CVE-2012-3143, CVE-2012-3159, CVE-2012-5068, CVE-2012-5083, CVE-2012-5084,
CVE-2012-5086, CVE-2012-5089)
Information disclosure vulnerabilities were discovered in the OpenJDK JR
Red Hat
JDK: unspecified vulnerability (JMX)
vendor_redhat·2012-10-16·CVSS 10.0
CVE-2012-3143 [CRITICAL] JDK: unspecified vulnerability (JMX)
JDK: unspecified vulnerability (JMX)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Red Hat
OpenJDK: RMIConnectionImpl insufficient access control checks (JMX, 7198296)
vendor_redhat·2012-10-16·CVSS 10.0
CVE-2012-5089 [CRITICAL] OpenJDK: RMIConnectionImpl insufficient access control checks (JMX, 7198296)
OpenJDK: RMIConnectionImpl insufficient access control checks (JMX, 7198296)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-3143.
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00022.htmlhttp://marc.info/?l=bugtraq&m=135542848327757&w=2http://marc.info/?l=bugtraq&m=135758563611658&w=2http://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1465.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51141http://secunia.com/advisories/51315http://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51328http://secunia.com/advisories/51390http://secunia.com/advisories/51438http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21620037http://www-01.ibm.com/support/docview.wss?uid=swg21620575http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www-01.ibm.com/support/docview.wss?uid=swg21631786http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-023/index.htmlhttp://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56055http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79419https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16686http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00022.htmlhttp://marc.info/?l=bugtraq&m=135542848327757&w=2http://marc.info/?l=bugtraq&m=135758563611658&w=2http://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1465.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51141http://secunia.com/advisories/51315http://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51328http://secunia.com/advisories/51390http://secunia.com/advisories/51438http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21620037http://www-01.ibm.com/support/docview.wss?uid=swg21620575http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www-01.ibm.com/support/docview.wss?uid=swg21631786http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-023/index.htmlhttp://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56055http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/79419https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16686
2012-10-16
Published