EXPOSURES › CVE-2012-0507
CVE-2012-0507
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments.
CVE-2012-0507 allowed remote code execution via an incorrect type vulnerability in Java's Concurrency component. This is a critical risk for DIB organizations using Java, as it can lead to system compromise and non-compliance with NIST 800-171. Immediate patching and vulnerability scanning are essential.
Shame score — The vulnerability's age and active exploitation by ransomware demonstrates a failure to maintain a secure software supply chain and promptly address known risks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |