Executive brief
A type confusion vulnerability in the AtomicReferenceArray class implementation of the Java Runtime Environment (JRE) Concurrency component allows remote attackers to bypass sandbox restrictions or cause a denial of service. The flaw occurs because the implementation fails to ensure the array is of the Object[] type, enabling arbitrary code execution.
Affected products
- Oracle Java SE 7 Update 2 and earlier
- Oracle Java SE 6 Update 30 and earlier
- Oracle Java SE 5.0 Update 33 and earlier
Timeline
- 2012-02: disclosed: Oracle February 2012 Critical Patch Update (CPU)
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog