Junglewise Threat Intelligence

CVE-2012-1723: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVE-2012-1723 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE JDK. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Hotspot component of Oracle Java SE allows remote attackers to execute arbitrary code. The flaw impacts confidentiality, integrity, and availability and has been observed being exploited in the wild.

Affected products

  • Oracle Java SE Runtime Environment (JRE) 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier
  • Oracle Java SE JDK 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier

Timeline

  • 2012-06-12: advisory: Oracle Critical Patch Update published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats