CVE-2012-1723
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 94% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
93.7%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
Security-Teams sollten umgehend alle betroffenen Oracle Java SE Installationen identifizieren und priorisiert patchen, um das Risiko einer Kompromittierung zu minimieren. Da die Schwachstelle aktiv ausgenutzt wird, ist ein schnelles Handeln unerlässlich, um potenzielle Angriffe abzuwehren und die Systemintegrität zu gewährleisten.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Referenzen
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html
- http://marc.info/?l=bugtraq&m=134496371727681&w=2
- http://rhn.redhat.com/errata/RHSA-2012-0734.html
- http://secunia.com/advisories/51080
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://www.ibm.com/support/docview.wss?uid=swg21615246
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:095
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
- http://www.securityfocus.com/bid/53960
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3...