CVE-2012-4820

Modified
Published: 11 Jan 2013, 00:00
Last modified:06 Aug 2024, 20:50

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
8.46% LOW
8% probability -0.90%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Jan 2013, 00:00
Published
Vulnerability first disclosed
06 Aug 2024, 20:50
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 8.46% Percentile: 93%

Affected Systems

  • ibmjava

    ≥ 1.4.2, ≤ 1.4.2.13.13 | ≥ 5.0.0.0, ≤ 5.0.14.0 | ≥ 6.0.0.0, ≤ 6.0.11.0 | ≥ 7.0.0.0, ≤ 7.0.2.0

  • ibmlotus_domino

    8.0 | 8.0.1 | 8.0.2 | 8.0.2.1 | 8.0.2.2 | 8.0.2.3 | 8.0.2.4 | 8.5.0 | 8.5.0.1 | 8.5.1 | 8.5.1.1 | 8.5.1.2 | 8.5.1.3 | 8.5.1.4 | 8.5.1.5 | 8.5.2.0 | 8.5.2.1 | 8.5.2.2 | 8.5.2.3 | 8.5.2.4 | 8.5.3.0 | 8.5.3.1 | 8.5.3.2

  • ibmlotus_notes

    8.0 | 8.0.0 | 8.0.1 | 8.0.2 | 8.0.2.0 | 8.0.2.1 | 8.0.2.2 | 8.0.2.3 | 8.0.2.4 | 8.0.2.5 | 8.0.2.6 | 8.5 | 8.5.0.0 | 8.5.0.1 | 8.5.1 | 8.5.1.0 | 8.5.1.1 | 8.5.1.2 | 8.5.1.3 | 8.5.1.4 | 8.5.1.5 | 8.5.2.0 | 8.5.2.1 | 8.5.2.2 | 8.5.2.3 | 8.5.3 | 8.5.3.1 | 8.5.3.2 | 8.5.4

  • ibmlotus_notes_sametime

    8.0.80407 | 8.0.80822 | 8.5.1.20100709-1631

  • ibmlotus_notes_traveler

    8.0 | 8.0.1 | 8.0.1.2 | 8.0.1.3 | 8.5.0.0 | 8.5.0.1 | 8.5.0.2 | 8.5.1.1 | 8.5.1.2 | 8.5.1.3 | 8.5.2.1 | 8.5.3 | 8.5.3.1 | 8.5.3.2 | 8.5.3.3 | 8.5.3.3:interim_fix_1

  • ibmrational_change

    4.7 | 5.1 | 5.2 | 5.3

  • ibmrational_host_on-demand

    1.6.0.12 | 8.0.8.0 | 9.0.8.0 | 10.0.9.0 | 10.0.10.0 | 11.0.3.0 | 11.0.4.0 | 11.0.5.0 | 11.0.5.1 | 11.0.6.0 | 11.0.6.1

  • ibmservice_delivery_manager

    7.2.1.0 | 7.2.2.0

  • ibmsmart_analytics_system_5600

    7200

  • ibmsmart_analytics_system_5600_software

    na | 9.7

  • ibmtivoli_monitoring

    6.1.0 | 6.1.0.7 | 6.2.0 | 6.2.0.1 | 6.2.0.2 | 6.2.0.3 | 6.2.1 | 6.2.1.0 | 6.2.1.1 | 6.2.1.2 | 6.2.1.3 | 6.2.1.4 | 6.2.2 | 6.2.2.0 | 6.2.2.1 | 6.2.2.2 | 6.2.2.3 | 6.2.2.4 | 6.2.2.5 | 6.2.2.6 | 6.2.2.7 | 6.2.2.8 | 6.2.2.9 | 6.2.3 | 6.2.3.0 | 6.2.3.1 | 6.2.3.2

  • ibmtivoli_remote_control

    5.1.2

  • ibmwebsphere_real_time

    2.0 | 3.0

References (25)