Skip to content
COOEY

EXPOSURES › CVE-2012-0507

CVE-2012-0507

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-0507 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Oracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments.

CVE-2012-0507 allowed remote code execution via an incorrect type vulnerability in Java's Concurrency component. This is a critical risk for DIB organizations using Java, as it can lead to system compromise and non-compliance with NIST 800-171. Immediate patching and vulnerability scanning are essential.

Shame score — The vulnerability's age and active exploitation by ransomware demonstrates a failure to maintain a secure software supply chain and promptly address known risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized