EXPOSURES › CVE-2012-1723
CVE-2012-1723
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical, actively exploited Java vulnerability allows remote code execution, impacting systems using outdated Java SE Runtime Environments (JRE).
CVE-2012-1723 is an Oracle Java SE JRE vulnerability allowing remote attackers to affect confidentiality, integrity, and availability through unknown vectors. DIB organizations using vulnerable Java installations face significant risk of compromise, potentially impacting CMMC compliance and requiring remediation. Immediately patch Java SE to the latest version.
Shame score — The vulnerability's age and active exploitation despite available patches demonstrates a failure to maintain basic security hygiene, significantly increasing risk exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |