Skip to content
COOEY

EXPOSURES › CVE-2012-4681

CVE-2012-4681

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-4681 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Oracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly.

CVE-2012-4681 in Oracle Java SE enabled arbitrary code execution, and is currently being exploited in the wild, often linked to ransomware. DIB organizations using vulnerable Java installations face significant exposure, potential compliance failures (NIST 800-171 controls 3.a, 3.b, 4.a), and should immediately patch or mitigate the risk.

Shame score — The vulnerability's age and ongoing exploitation despite available patches indicates a serious lack of proactive patching and vulnerability management, contributing to a significant risk profile.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized