CVE-2012-5074
published 2012-10-16CVE-2012-5074: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect…
PriorityP341medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
3.12%
86.4th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality and integrity, related to JAX-WS.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2012-10-26·CVSS 10.0
CVE-2012-1531 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Several information disclosure vulnerabilities were discovered in the
OpenJDK JRE. (CVE-2012-3216, CVE-2012-5069, CVE-2012-5072, CVE-2012-5075,
CVE-2012-5077, CVE-2012-5085)
Vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure and data integrity. (CVE-2012-4416, CVE-2012-5071)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to cause a denial of service. (CVE-2012-1531, CVE-2012-1532, CVE-2012-1533,
CVE-2012-3143, CVE-2012-3159, CVE-2012-5068, CVE-2012-5083, CVE-2012-5084,
CVE-2012-5086, CVE-2012-5089)
Information disclosure vulnerabilities were discovered in the OpenJDK JR
Red Hat
OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
vendor_redhat·2012-10-16·CVSS 6.4
CVE-2012-5074 [MEDIUM] OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality and integrity, related to JAX-WS.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-9j6r-hxv4-2h2w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c
ghsa_unreviewed·2022-05-17
CVE-2012-5074 [MEDIUM] GHSA-9j6r-hxv4-2h2w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality and integrity, related to JAX-WS.
No detection rules found.
Bugzilla
CVE-2012-5074 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
bugzilla·2012-10-11·CVSS 6.4
CVE-2012-5074 [MEDIUM] CVE-2012-5074 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
CVE-2012-5074 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. This update lists those packages as restricted in the java.security file.
Note that the addition of the mentioned packages to the package.access properly list is tracked under CVE-2012-5076 and CVE-2012-5074 (see also bug 865352).
Discussion:
Fixed now in Oracle JDK 7u9.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
---
This issue has been addressed in following products:
Red Hat Enterprise Li
Bugzilla
CVE-2012-5076 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7163198)
bugzilla·2012-10-11·CVSS 6.4
CVE-2012-5076 [MEDIUM] CVE-2012-5076 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7163198)
CVE-2012-5076 OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7163198)
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. This update lists those packages as restricted in the java.security file.
Note that the addition of the mentioned packages to the package.access properly list is tracked under CVE-2012-5076 and CVE-2012-5074 (see also bug 865359).
Discussion:
Fixed now in Oracle JDK 7u9.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
---
This issue has been addressed in following products:
Red Hat Enterprise Li
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1386.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://secunia.com/advisories/51029http://secunia.com/advisories/51326http://secunia.com/advisories/51390http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56056https://exchange.xforce.ibmcloud.com/vulnerabilities/79426https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16668http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1386.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1391.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1467.htmlhttp://secunia.com/advisories/51029http://secunia.com/advisories/51326http://secunia.com/advisories/51390http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.htmlhttp://www.securityfocus.com/bid/56056https://exchange.xforce.ibmcloud.com/vulnerabilities/79426https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16668
2012-10-16
Published