EXPOSURES › CVE-2012-5076
CVE-2012-5076
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution.
The default Java security properties failed to restrict access to internal packages, allowing untrusted code to bypass sandbox restrictions and execute arbitrary commands. DIB organizations must ensure Java is patched and hardened, as this flaw was actively exploited in the wild and represents a severe, avoidable security oversight.
Shame score — Oracle shipped a widely used platform with default configurations that allowed sandbox bypass, a severe and avoidable flaw that was actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |