CVE-2012-1682

Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 30 Aug 2012, 23:00
Last modified:06 Aug 2024, 19:08

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
2.93% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Aug 2012, 23:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:08
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."

CVSS Metrics

  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 2.93% Percentile: 87%

Affected Systems

  • oraclejdk

    ≤ 1.7.0 | 1.7.0 | 1.7.0:update1 | 1.7.0:update2 | 1.7.0:update3 | 1.7.0:update4 | 1.7.0:update5

  • oraclejre

    ≤ 1.7.0 | 1.7.0 | 1.7.0:update1 | 1.7.0:update2 | 1.7.0:update3 | 1.7.0:update4 | 1.7.0:update5

References (13)