EXPOSURES › CVE-2012-4681
CVE-2012-4681
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly.
CVE-2012-4681 in Oracle Java SE enabled arbitrary code execution, and is currently being exploited in the wild, often linked to ransomware. DIB organizations using vulnerable Java installations face significant exposure, potential compliance failures (NIST 800-171 controls 3.a, 3.b, 4.a), and should immediately patch or mitigate the risk.
Shame score — The vulnerability's age and ongoing exploitation despite available patches indicates a serious lack of proactive patching and vulnerability management, contributing to a significant risk profile.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |