CVE-2012-0507 Details
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE has been identified, specifically in versions 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier. This vulnerability relates to the AtomicReferenceArray class, which does not properly verify that the array is of the expected Object[] type. As a result, remote attackers could exploit this flaw to cause a denial-of-service by crashing the Java Virtual Machine or to bypass Java's sandbox restrictions, which are designed to limit the capabilities of untrusted code.
Users can upgrade to Oracle Java SE 7 Update 3, 6 Update 31, or 5.0 Update 34. Instructions for downloading these versions are available on the Oracle website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2022References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | Mar 3, 2022 | Mar 24, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sun jre | 1.5.0 - 1.5.0 update1 1.5.0 update10 1.5.0 update11 1.5.0 update12 1.5.0 update13 1.5.0 update14 1.5.0 update15 1.5.0 update16 1.5.0 update17 1.5.0 update18 1.5.0 update19 1.5.0 update2 1.5.0 update20 1.5.0 update21 1.5.0 update22 1.5.0 update23 1.5.0 update24 1.5.0 update25 1.5.0 update26 1.5.0 update27 1.5.0 update28 1.5.0 update29 1.5.0 update3 1.5.0 update31 1.5.0 update33 1.5.0 update4 1.5.0 update5 1.5.0 update6 1.5.0 update7 1.5.0 update8 1.5.0 update9 1.6.0 - 1.6.0 update_1 1.6.0 update_10 1.6.0 update_11 1.6.0 update_12 1.6.0 update_13 1.6.0 update_14 1.6.0 update_15 1.6.0 update_16 1.6.0 update_17 1.6.0 update_18 1.6.0 update_19 1.6.0 update_2 1.6.0 update_20 1.6.0 update_21 1.6.0 update_3 1.6.0 update_4 1.6.0 update_5 1.6.0 update_6 1.6.0 update_7 |
CPE
Remediation
| |
| oracle jre | 1.6.0 update22 1.6.0 update23 1.6.0 update24 1.6.0 update25 1.6.0 update26 1.6.0 update27 1.6.0 update29 1.6.0 update30 1.7.0 - 1.7.0 update1 1.7.0 update2 |
CPE
Remediation
| |
| debian debian linux | 6.0 7.0 |
CPE
Remediation
| |
| suse linux enterprise desktop | 10 sp4 |
CPE
Remediation
| |
| suse linux enterprise java | 10 sp4 11 sp1 |
CPE
Remediation
| |
| suse linux enterprise server | 10 sp4 11 sp1 11 sp2 |
CPE
Remediation
| |
| suse linux enterprise software development kit | 11 sp1 11 sp2 |
CPE
Remediation
| |
Change History
25 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Modified Analysis | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
| Jan 6, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 26, 2024 | Modified Analysis | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| Dec 29, 2017 | CVE Modified | [email protected] |
| Dec 22, 2017 | CVE Modified | [email protected] |
| Aug 23, 2016 | CVE Modified | [email protected] |
| Jun 8, 2012 | Initial Analysis | [email protected] |