SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0547

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly…

LOW 0.0EPSS 12.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

CVSS 2.0
0.0 LOWAV:N/AC:L/Au:N/C:N/I:N/A:N
EPSS
12.47% probability · 96th percentile
CISA KEV
Not listed
Affected
oracle/jdk · oracle/jre · sun/jdk · sun/jre
Source
secalert_us@oracle.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.