CVE-2012-4681 is a critical remote code execution vulnerability affecting Oracle Java SE 7 Update 6 and earlier, as well as Red Hat products utilizing these Java versions. Attackers can bypass SecurityManager restrictions via a crafted applet, leveraging specific Java classes and reflection to execute arbitrary code. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this flaw allows for complete compromise of confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild since August 2012, including in known ransomware campaigns, with publicly available Metasploit modules and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:-:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update1:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update11:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.