CVE-2012-5071 — Oracle JDK vulnerability
6 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
3.1%
top 13.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateMay 14
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity, related to JMX.
CVSS vector
AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-q7x9-8wcv-c5wh: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5↗2022-05-14
CVEList▶
CVE-2012-5071: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5↗2012-10-16
📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2012-5071 OpenJDK: DescriptorSupport insufficient package access checks (JMX, 7192975)↗2012-10-11