CVE-2012-0547 describes an unspecified vulnerability within the Java Runtime Environment (JRE) in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, specifically impacting the AWT component. Oracle initially categorized it as a "security-in-depth issue" not directly exploitable but capable of aggravating other vulnerabilities. Despite a CVSS score of 0.0, indicating no direct impact, exploit intelligence shows a Metasploit module (EDB-20865) for Remote Code Execution in Java 7 Applets, contradicting Oracle's initial assessment. The vulnerability has garnered significant community discussion and media coverage, with articles from Krebs on Security and SecurityWeek highlighting its critical nature and the release of fixes. While not on the KEV or Hot List, the existence of public exploit code and media attention suggest a higher practical risk than its CVSS score implies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.