Vulnerability Name:

CVE-2012-0500 (CCN-73188)

Assigned:2012-02-14
Published:2012-02-14
Updated:2022-05-13
Summary:Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.6 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-0500

Source: SUSE
Type: UNKNOWN
SUSE-SU-2012:0603

Source: HP
Type: UNKNOWN
HPSBUX02757

Source: HP
Type: UNKNOWN
HPSBUX02784

Source: HP
Type: UNKNOWN
HPSBMU02799

Source: HP
Type: UNKNOWN
SSRT100867

Source: CCN
Type: RHSA-2012-0139
Critical: java-1.6.0-sun security update

Source: CCN
Type: RHSA-2012-0514
Critical: java-1.6.0-ibm security update

Source: REDHAT
Type: UNKNOWN
RHSA-2012:0514

Source: CCN
Type: RHSA-2013-1455
Low: Red Hat Network Satellite server IBM Java Runtime security update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1455

Source: CCN
Type: SA48009
Oracle Java SE Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
48073

Source: SECUNIA
Type: UNKNOWN
48589

Source: CCN
Type: SA48854
IBM 31-bit SDK for z/OS and IBM 64-bit SDK for z/OS Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
48950

Source: CCN
Type: Apple KB HT5228
About the security content of Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7

Source: CCN
Type: IBM Security Bulletin 1616778
Potential security vulnerability in IBM Tivoli Monitoring with JAVA® using untrusted Java WebStart applications or Java applets

Source: CCN
Type: IBM APAR PM59971
GEN APAR: 31-BIT JAVA FOR Z/OS SDK 6 SERVICE REFRESH (SR10 FP1) THE PTF FOR THIS APAR DELIVERS THE LATEST CUMULATIVE SERVICE

Source: CCN
Type: IBM APAR PM59978
GEN APAR: 64-BIT JAVA FOR Z/OS SDK 6 SERVICE REFRESH (SR10 FP1) THE PTF FOR THIS APAR DELIVERS THE LATEST CUMULATIVE SERVICE

Source: CCN
Type: Oracle Java SE Critical Patch Update Advisory - February 2012
Oracle Java SE Critical Patch Update Advisory - February 2012

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html

Source: CCN
Type: OSVDB ID: 79227
Oracle Java SE Deployment Component java-vm-args Command Argument Injection Remote Code Execution

Source: BID
Type: UNKNOWN
52015

Source: CCN
Type: BID-52015
Oracle Java SE CVE-2012-0500 Java Runtime Environment Remote Code Execution Vulnerability

Source: XF
Type: UNKNOWN
javase-jre-cve20120500(73188)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:14844

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [02-24-2012]

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2012-0500

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:-:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:*:update30:*:*:*:*:*:* (Version <= 1.6.0)
  • OR cpe:/a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update22:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:oracle:jre:*:update2:*:*:*:*:*:* (Version <= 1.7.0)
  • OR cpe:/a:oracle:jre:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:update1:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:oracle:javafx:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:*:*:*:*:*:*:*:* (Version <= 2.0.2)
  • OR cpe:/a:oracle:javafx:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.2.2:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:javafx:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:javafx:2.0.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.8:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.8:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.7.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20120500
    V
    CVE-2012-0500
    2022-05-20
    oval:org.opensuse.security:def:33039
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:32982
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:33088
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:28942
    P
    Security update for java-1_8_0-ibm (Important)
    2021-02-26
    oval:org.opensuse.security:def:32682
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28365
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33832
    P
    Security update for gnutls (Important)
    2020-12-01
    oval:org.opensuse.security:def:29084
    P
    Security update for dnsmasq (Important)
    2020-12-01
    oval:org.opensuse.security:def:32826
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28564
    P
    Security update for OpenJDK 1.6
    2020-12-01
    oval:org.opensuse.security:def:32363
    P
    Security update for sudo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29145
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28706
    P
    Security update for gstreamer-0_10-plugins-bad
    2020-12-01
    oval:org.opensuse.security:def:32375
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29819
    P
    Security update for IBM Java 1.6.0
    2020-12-01
    oval:org.opensuse.security:def:33127
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32588
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28354
    P
    Security update for pidgin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33194
    P
    libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29045
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32739
    P
    libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28433
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33871
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:29101
    P
    Recommended update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28649
    P
    Security update for CUPS
    2020-12-01
    oval:org.opensuse.security:def:32364
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:29783
    P
    Security update for gpg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28790
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32453
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28353
    P
    Security update for pidgin (Important)
    2020-12-01
    oval:org.opensuse.security:def:33150
    P
    libgcc_s1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28996
    P
    Security update for gnutls
    2020-12-01
    oval:org.mitre.oval:def:19583
    V
    HP-UX Running Java, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
    2015-04-20
    oval:org.mitre.oval:def:21404
    P
    RHSA-2012:0514: java-1.6.0-ibm security update (Critical)
    2015-03-09
    oval:org.mitre.oval:def:23323
    P
    ELSA-2012:0514: java-1.6.0-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:23638
    P
    ELSA-2012:0139: java-1.6.0-sun security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:21410
    P
    RHSA-2012:0139: java-1.6.0-sun security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:14844
    V
    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
    2013-01-28
    oval:com.redhat.rhsa:def:20120514
    P
    RHSA-2012:0514: java-1.6.0-ibm security update (Critical)
    2012-04-24
    oval:com.redhat.rhsa:def:20120139
    P
    RHSA-2012:0139: java-1.6.0-sun security update (Critical)
    2012-02-16
    oval:com.ubuntu.precise:def:20120500000
    V
    CVE-2012-0500 on Ubuntu 12.04 LTS (precise) - medium.
    2012-02-15
    BACK
    sun jre 1.6.0 update_3
    sun jre 1.6.0 update_5
    sun jre 1.6.0 update_13
    sun jre 1.6.0 update_1
    sun jre 1.6.0 update_2
    sun jre 1.6.0 update_16
    sun jre 1.6.0 update_20
    sun jre 1.6.0 update_15
    sun jre 1.6.0 update_6
    sun jre 1.6.0 update_19
    sun jre 1.6.0 update_21
    sun jre 1.6.0
    sun jre 1.6.0 update_17
    oracle jre 1.6.0 update27
    oracle jre 1.6.0 update29
    oracle jre * update30
    sun jre 1.6.0 update_7
    sun jre 1.6.0 update_10
    sun jre 1.6.0 update_12
    sun jre 1.6.0 update_11
    oracle jre 1.6.0 update23
    oracle jre 1.6.0 update24
    sun jre 1.6.0 update_4
    sun jre 1.6.0 update_14
    oracle jre 1.6.0 update25
    oracle jre 1.6.0 update26
    sun jre 1.6.0 update_18
    oracle jre 1.6.0 update22
    oracle jre * update2
    oracle jre 1.7.0
    oracle jre 1.7.0 update1
    oracle javafx 1.2.3
    oracle javafx *
    oracle javafx 2.0
    oracle javafx 1.3.1
    oracle javafx 1.3.0
    oracle javafx 1.2
    oracle javafx 1.2.2
    oracle javafx 2.0
    oracle jre 1.7.0
    oracle jre 1.7.0 update1
    oracle jre 1.7.0 update2
    oracle javafx 1.3.1
    oracle javafx 1.2.3
    oracle javafx 1.2
    oracle javafx 1.3.0
    oracle javafx 1.2.2
    oracle javafx 2.0.2
    redhat rhel extras 4
    apple mac os x 10.6.8
    apple mac os x server 10.6.8
    redhat enterprise linux server supplementary 6
    redhat enterprise linux workstation supplementary 6
    redhat enterprise linux desktop supplementary 6
    redhat enterprise linux hpc node supplementary 6
    apple mac os x server 10.7.3
    apple mac os x 10.7.3