CVE-2012-4822
published 2013-01-11CVE-2012-4822: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.90%
93.4th percentile
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."
Affected
123 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | 1.4.2 – 1.4.2.13.13 | — |
| ibm | java | 5.0.0.0 – 5.0.14.0 | — |
| ibm | java | 6.0.0.0 – 6.0.11.0 | — |
| ibm | java | 7.0.0.0 – 7.0.2.0 | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: java.lang.class code execution
vendor_redhat·2012-11-13·CVSS 9.3
CVE-2012-4822 [CRITICAL] JDK: java.lang.class code execution
JDK: java.lang.class code execution
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
GHSA
GHSA-p39h-jmg2-h2pw: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6
ghsa_unreviewed·2022-05-14
CVE-2012-4822 [HIGH] GHSA-p39h-jmg2-h2pw: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1465.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://seclists.org/bugtraq/2012/Sep/38http://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51328http://secunia.com/advisories/51393http://secunia.com/advisories/51634http://www-01.ibm.com/support/docview.wss?uid=swg1IV29665http://www-01.ibm.com/support/docview.wss?uid=swg21615705http://www-01.ibm.com/support/docview.wss?uid=swg21615800http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21616594http://www-01.ibm.com/support/docview.wss?uid=swg21616616http://www-01.ibm.com/support/docview.wss?uid=swg21616617http://www-01.ibm.com/support/docview.wss?uid=swg21616652http://www-01.ibm.com/support/docview.wss?uid=swg21616708http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www-01.ibm.com/support/docview.wss?uid=swg21631786http://www.securityfocus.com/bid/55495https://exchange.xforce.ibmcloud.com/vulnerabilities/78766https://www-304.ibm.com/support/docview.wss?uid=swg21616546http://rhn.redhat.com/errata/RHSA-2012-1465.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://seclists.org/bugtraq/2012/Sep/38http://secunia.com/advisories/51326http://secunia.com/advisories/51327http://secunia.com/advisories/51328http://secunia.com/advisories/51393http://secunia.com/advisories/51634http://www-01.ibm.com/support/docview.wss?uid=swg1IV29665http://www-01.ibm.com/support/docview.wss?uid=swg21615705http://www-01.ibm.com/support/docview.wss?uid=swg21615800http://www-01.ibm.com/support/docview.wss?uid=swg21616490http://www-01.ibm.com/support/docview.wss?uid=swg21616594http://www-01.ibm.com/support/docview.wss?uid=swg21616616http://www-01.ibm.com/support/docview.wss?uid=swg21616617http://www-01.ibm.com/support/docview.wss?uid=swg21616652http://www-01.ibm.com/support/docview.wss?uid=swg21616708http://www-01.ibm.com/support/docview.wss?uid=swg21621154http://www-01.ibm.com/support/docview.wss?uid=swg21631786http://www.securityfocus.com/bid/55495https://exchange.xforce.ibmcloud.com/vulnerabilities/78766https://www-304.ibm.com/support/docview.wss?uid=swg21616546
2013-01-11
Published