{"id":"CVE-2012-0507","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.","cvssScore":9.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"},{"version":"2.0","score":10,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-843"],"resolved":"MITIGATION-CANDIDATE","published":"2012-06-07","lastModified":"2026-08-14","affectedProducts":[{"vendor":"sun","product":"jre","version":"1.5.0"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update1"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update10"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update11"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update12"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update13"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update14"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update15"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update16"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update17"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update18"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update19"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update2"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update20"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update21"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update22"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update23"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update24"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update25"},{"vendor":"sun","product":"jre","version":"1.5.0","update":"update26"}],"totalAffectedProducts":7,"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=788994","source":"patch-hint","tags":["bugzilla"]},{"url":"https://access.redhat.com/errata/RHSA-2012:0135","source":"redhat","tags":["ADVISORY","RHSA-2012:0135"]},{"url":"https://access.redhat.com/security/cve/CVE-2012-0507","source":"redhat","tags":["REPORT","RHSA-2012:0135"]},{"url":"https://access.redhat.com/errata/RHSA-2012:0322","source":"redhat","tags":["ADVISORY","RHSA-2012:0322"]},{"url":"http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx","source":"secalert_us@oracle.com","tags":["Broken Link","Third Party Advisory"]},{"url":"http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","source":"secalert_us@oracle.com","tags":["Issue Tracking","Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html","source":"secalert_us@oracle.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://marc.info/?l=bugtraq\u0026m=133364885411663\u0026w=2","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://marc.info/?l=bugtraq\u0026m=133365109612558\u0026w=2","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]}],"reasoning":{"decidingSource":"patch-hint","decidingReason":"Red Hat published an advisory () confirming a fix exists, and the linked Bugzilla ticket (https://bugzilla.redhat.com/show_bug.cgi?id=788994) points to the upstream OpenJDK source patch. That makes this CVE a candidate for an ARMR patch rule. No rule exists and none is scheduled: whether one can be derived depends on reading the actual change.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"no-match"},{"rule":"cna-maven-package","stage":"scope","outcome":"no-match"},{"rule":"known-cpe-product","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Matches known products: sun/jre, oracle/jre"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (bugzilla tier): https://bugzilla.redhat.com/show_bug.cgi?id=788994","decisive":true},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is CRITICAL — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"no-match","detail":"A KEV listing, a CISA verdict of active exploitation, or a reviewed exploit catalogue carries this CVE — somebody has published a working exploit, so it stays a candidate"}],"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=788994","patchHintTier":"bugzilla","affectedProducts":[{"vendor":"sun","product":"jre","isKnown":true,"cpe":"cpe:2.3:a:sun:jre:1.5.0:-:*:*:*:*:*:*","source":"yaml"},{"vendor":"oracle","product":"jre","isKnown":true,"cpe":"cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*","source":"yaml"},{"vendor":"debian","product":"debian_linux","isKnown":false,"cpe":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*"},{"vendor":"suse","product":"linux_enterprise_desktop","isKnown":false,"cpe":"cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*"},{"vendor":"suse","product":"linux_enterprise_java","isKnown":false,"cpe":"cpe:2.3:o:suse:linux_enterprise_java:10:sp4:*:*:*:*:*:*"},{"vendor":"suse","product":"linux_enterprise_server","isKnown":false,"cpe":"cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*"},{"vendor":"suse","product":"linux_enterprise_software_development_kit","isKnown":false,"cpe":"cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp1:*:*:*:*:*:*"}]},"oracleAdvisories":[{"advisory":"Java SE CPU Feb 2012","releaseType":"CPU","quarter":"2012-Q1","url":"https://www.oracle.com/security-alerts/javacpufeb2012.html","products":[{"product":"Oracle Java SE","component":"Java Runtime Environment","affectedVersions":"7 Update 2 and before, 6 Update 30 and before, 5.0 Update 33 and before"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/18679","title":"Java - AtomicReferenceArray Type Violation (Metasploit)","date":"2012-03-30"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["exploit-db"],"firstPOCDate":"2012-03-30"},"kev":{"inKEV":true,"dateAdded":"2022-03-03","dueDate":"2022-03-24","knownRansomwareUse":"Known"},"epss":{"available":true,"score":0.98113,"percentile":0.9991},"ssvc":{"available":true,"exploitation":"active","automatable":"yes","technicalImpact":"total"},"patchHintUrl":"https://bugzilla.redhat.com/show_bug.cgi?id=788994","patchHintTier":"bugzilla"}