CVE-2012-4681 Details
Description
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 6 and earlier versions allows remote attackers to execute arbitrary code. This is achieved by exploiting a crafted applet that bypasses SecurityManager restrictions. The vulnerability arises from the use of 'com.sun.beans.finder.ClassFinder' to access restricted classes from arbitrary packages, such as 'sun.awt.SunToolkit'. The exploit then uses reflection to access and modify private fields, effectively disabling the security manager and allowing unrestricted execution of Java code. This vulnerability was actively exploited in the wild in August 2012.
Users are advised to update to Oracle Java SE 7 Update 7, which addresses this vulnerability. Instructions for downloading the update are available on the Oracle website. Users can also disable the Java plug-in in their web browser to protect against this and future vulnerabilities.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2022References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | Mar 3, 2022 | Mar 24, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| oracle jdk | 1.6.0 - 1.6.0 update1 1.6.0 update10 1.6.0 update11 1.6.0 update12 1.6.0 update13 1.6.0 update14 1.6.0 update15 1.6.0 update16 1.6.0 update17 1.6.0 update18 1.6.0 update19 1.6.0 update2 1.6.0 update20 1.6.0 update21 1.6.0 update22 1.6.0 update23 1.6.0 update24 1.6.0 update25 1.6.0 update26 1.6.0 update27 1.6.0 update29 1.6.0 update3 1.6.0 update30 1.6.0 update31 1.6.0 update32 1.6.0 update33 1.6.0 update34 1.6.0 update4 1.6.0 update5 1.6.0 update6 1.6.0 update7 1.6.0 update8 1.6.0 update9 1.7.0 - 1.7.0 update1 1.7.0 update2 1.7.0 update3 1.7.0 update4 1.7.0 update5 1.7.0 update6 |
CPE
Remediation
| |
| oracle jre | 1.6.0 - 1.6.0 update1 1.6.0 update10 1.6.0 update11 1.6.0 update12 1.6.0 update13 1.6.0 update14 1.6.0 update15 1.6.0 update16 1.6.0 update17 1.6.0 update18 1.6.0 update19 1.6.0 update2 1.6.0 update20 1.6.0 update21 1.6.0 update22 1.6.0 update23 1.6.0 update24 1.6.0 update25 1.6.0 update26 1.6.0 update27 1.6.0 update29 1.6.0 update3 1.6.0 update30 1.6.0 update31 1.6.0 update32 1.6.0 update33 1.6.0 update34 1.6.0 update4 1.6.0 update5 1.6.0 update6 1.6.0 update7 1.6.0 update9 1.7.0 - 1.7.0 update1 1.7.0 update2 1.7.0 update3 1.7.0 update4 1.7.0 update5 1.7.0 update6 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 6.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.3 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 |
CPE
Remediation
| |
Change History
45 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 14, 2025 | Modified Analysis | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
| Jan 6, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 21, 2022 | Modified Analysis | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| Aug 5, 2017 | CVE Modified | [email protected] |
| Oct 11, 2013 | Initial Analysis | [email protected] |