Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4820

Опубликовано: 13 нояб. 2012
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.7.0-ibmAffected
Red Hat Network Satellite Server v 5.4java-1.6.0-ibmFixedRHSA-2013:145523.10.2013
Red Hat Network Satellite Server v 5.5java-1.6.0-ibmFixedRHSA-2013:145623.10.2013
Supplementary for Red Hat Enterprise Linux 5java-1.5.0-ibmFixedRHSA-2012:146515.11.2012
Supplementary for Red Hat Enterprise Linux 5java-1.6.0-ibmFixedRHSA-2012:146615.11.2012
Supplementary for Red Hat Enterprise Linux 5java-1.4.2-ibmFixedRHSA-2012:148522.11.2012
Supplementary for Red Hat Enterprise Linux 6java-1.5.0-ibmFixedRHSA-2012:146515.11.2012
Supplementary for Red Hat Enterprise Linux 6java-1.6.0-ibmFixedRHSA-2012:146615.11.2012
Supplementary for Red Hat Enterprise Linux 6java-1.7.0-ibmFixedRHSA-2012:146715.11.2012

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=876386JDK: java.lang.reflect.Method invoke() code execution

EPSS

Процентиль: 93%
0.09366
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

debian
около 13 лет назад

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and e ...

github
больше 3 лет назад

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

EPSS

Процентиль: 93%
0.09366
Низкий

6.8 Medium

CVSS2