CVE-2012-5072 — Oracle JDK vulnerability
6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
2.3%
top 15.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateMay 14
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality via unknown vectors related to Security.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-p34p-28jp-wfv2: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow↗2022-05-14
CVEList▶
CVE-2012-5072: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allow↗2012-10-16
📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2012-5072 OpenJDK: AccessController.doPrivilegedWithCombiner() information disclosure (Security, 7172522)↗2012-10-11