CVE-2012-4820 - CVE House
Back to Database
Status published Critical CVE-2012-4820

Unspecified vulnerability in the JRE component in IBM Java 7...

Vulnerability Description

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-4820

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

java, lotus domino, lotus notes, lotus notes sametime, lotus notes traveler, rational change, rational host on-demand, service delivery manager, smart analytics system 5600 software, tivoli monitoring, tivoli remote control, websphere real time, 5.0, 5.1, 5.1.1, smart analytics system 5600
Vulnerable Versions:
1.4.2, 5.0.0.0, 6.0.0.0, 7.0.0.0, 8.0, 8.0.1, 8.0.2, 8.0.2.1, 8.0.2.2, 8.0.2.3, 8.0.2.4, 8.5.0, 8.5.0.1, 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.1.3, 8.5.1.4, 8.5.1.5, 8.5.2.0, 8.5.2.1, 8.5.2.2, 8.5.2.3, 8.5.2.4, 8.5.3.0, 8.5.3.1, 8.5.3.2, 8.0.0, 8.0.2.0, 8.0.2.5, 8.0.2.6, 8.5, 8.5.0.0, 8.5.1.0, 8.5.3, 8.5.4, 8.0.80407, 8.0.80822, 8.5.1.20100709-1631, 8.0.1.2, 8.0.1.3, 8.5.0.2, 8.5.3.3, 4.7, 5.1, 5.2, 5.3, 1.6.0.12, 8.0.8.0, 9.0.8.0, 10.0.9.0, 10.0.10.0, 11.0.3.0, 11.0.4.0, 11.0.5.0, 11.0.5.1, 11.0.6.0, 11.0.6.1, 7.2.1.0, 7.2.2.0, 9.7, 6.1.0, 6.1.0.7, 6.2.0, 6.2.0.1, 6.2.0.2, 6.2.0.3, 6.2.1, 6.2.1.0, 6.2.1.1, 6.2.1.2, 6.2.1.3, 6.2.1.4, 6.2.2, 6.2.2.0, 6.2.2.1, 6.2.2.2, 6.2.2.3, 6.2.2.4, 6.2.2.5, 6.2.2.6, 6.2.2.7, 6.2.2.8, 6.2.2.9, 6.2.3, 6.2.3.0, 6.2.3.1, 6.2.3.2, 5.1.2, 2.0, 3.0, 7200

Timeline

Official Publish: January 11th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.