Skip to content
COOEY

EXPOSURES › CVE-2012-5076

CVE-2012-5076

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-5076 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrce

Oracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution.

The default Java security properties failed to restrict access to internal packages, allowing untrusted code to bypass sandbox restrictions and execute arbitrary commands. DIB organizations must ensure Java is patched and hardened, as this flaw was actively exploited in the wild and represents a severe, avoidable security oversight.

Shame score — Oracle shipped a widely used platform with default configurations that allowed sandbox bypass, a severe and avoidable flaw that was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized