cbcvebase.
CVE-2012-5081
published 2012-10-16

CVE-2012-5081: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and…

PriorityP180medium5CVSS 2.0
AVNACLAuNCNINAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
45.11%
98.7th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to JSSE.

Affected

92 ranges· showing 25
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk<= 1.4.2_38
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre<= 1.4.2_38
oraclejre
oraclejre
oraclejrockitr27.7.0 – r27.7.3
oraclejrockitr28.2.0 – r28.2.4
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk
sunjdk

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by SSL/TLS handshake records containing an overly large data length value sent to a JSSE-based SSL/TLS server; monitor for malformed TLS handshake records with anomalously large length fields targeting Java SSL/TLS servers.
  • ·Affected versions include Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier; fixed in Oracle JDK 7u9 and 6u37.
  • ·IcedTea6 versions 1.10.10 and 1.11.5 include the fix; IcedTea7 versions 2.1.3, 2.2.3, and 2.3.3 include the fix.
  • ·The attack vector is unauthenticated and remote — no prior authentication is required to trigger the denial of service against a JSSE SSL/TLS server.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck5.0MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.