Executive brief
The default Java security properties configuration failed to restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. This allows untrusted Java applications or applets to bypass sandbox restrictions and affect confidentiality, integrity, and availability via JAX-WS.
Affected products
- Oracle Java SE 7 Update 7 and earlier
- Oracle JRE 7 Update 7 and earlier
- Oracle JDK 7 Update 7 and earlier
Timeline
- 2012-10-16: patched: Oracle Critical Patch Update October 2012
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: disclosed: NVD publication date