CVE-2012-4681
Description
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using 'reflection with a trusted immediate caller' to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Access Control
IncompleteCommon Consequences
Applicable Platforms
Java 7 Applet - Remote Code Execution (Metasploit)
Verified Metasploit Framework (MSF)Java 7 Applet - Remote Code Execution (Metasploit)
View Exploit Code →Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update5:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update11:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update12:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update3:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update11:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update3:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update18:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update14:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update17:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update13:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update14:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update7:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:-:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update20:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update21:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update2:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update9:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update9:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update6:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update21:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update6:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update20:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update19:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update19:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update12:*:*:*:*:*:*
Enterprise Linux Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update4:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*
Enterprise Linux Server by Redhat
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update13:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update16:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:-:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update1:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update4:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update10:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update15:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update16:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update7:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update2:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update17:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update5:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
Enterprise Linux Workstation by Redhat
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:-:*:*:*:*:*:*
Enterprise Linux Desktop by Redhat
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update1:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update18:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*
Jre by Oracle
cpe:2.3:a:oracle:jre:1.6.0:update15:*:*:*:*:*:*
Jdk by Oracle
cpe:2.3:a:oracle:jdk:1.6.0:update8:*:*:*:*:*:*