CVE-2012-5089 — Oracle JDK vulnerability
7 documents6 sources
Severity
7.6HIGHNVD
CNA10.0
EPSS
10.9%
top 6.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateMay 14
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-3143.
CVSS vector
AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0
Affected Packages4 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-rpr7-2rf2-926r: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5↗2022-05-14
CVEList▶
CVE-2012-5089: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5↗2012-10-16
📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2012-5089 OpenJDK: RMIConnectionImpl insufficient access control checks (JMX, 7198296)↗2012-10-11