Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
BID:56079
Info
Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
| Bugtraq ID: | 56079 |
| Class: | Unknown |
| CVE: |
CVE-2012-5070 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2012 12:00AM |
| Updated: | Apr 13 2015 09:49PM |
| Credit: | Oracle |
| Vulnerable: |
VMWare VirtualCenter 2.5 VMWare Vcenter Update Manager 5.1 VMWare Vcenter Update Manager 5.0 VMWare vCenter Server 5.0 VMWare vCenter Server 4.1 VMWare vCenter Server 4.0 VMWare ESX 4.1 VMWare ESX 4.0 VMWare ESX 3.5 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Software Development Kit 11 SP2 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Java 11 SP2 Sun JRE (Windows Production Release) 1.7 Sun JRE (Solaris Production Release) 1.7 Sun JRE (Linux Production Release) 1.7 S.u.S.E. openSUSE 12.2 Redhat Enterprise Linux Workstation Supplementary 6 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Server Supplementary 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Supplementary 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Oracle Solaris 11.1 Oracle JRE (Windows Production Release) 1.7.0_7 Oracle JRE (Windows Production Release) 1.7.0_4 Oracle JRE (Windows Production Release) 1.7.0_2 Oracle JRE (Solaris Production Release) 1.7.0_7 Oracle JRE (Solaris Production Release) 1.7.0_4 Oracle JRE (Solaris Production Release) 1.7.0_2 Oracle JRE (Linux Production Release) 1.7.0_7 Oracle JRE (Linux Production Release) 1.7.0_4 Oracle JRE (Linux Production Release) 1.7.0_2 Oracle JDK (Windows Production Release) 1.7 Oracle JDK (Windows Production Release) 1.7.0_7 Oracle JDK (Windows Production Release) 1.7.0_4 Oracle JDK (Windows Production Release) 1.7.0_2 Oracle JDK (Solaris Production Release) 1.7 Oracle JDK (Solaris Production Release) 1.7.0_7 Oracle JDK (Solaris Production Release) 1.7.0_4 Oracle JDK (Solaris Production Release) 1.7.0_2 Oracle JDK (Linux Production Release) 1.7 Oracle JDK (Linux Production Release) 1.7.0_7 Oracle JDK (Linux Production Release) 1.7.0_4 Oracle JDK (Linux Production Release) 1.7.0_2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 OpenJDK OpenJDK 7 OpenJDK OpenJDK 6 IcedTea IcedTea 2.3.2 IcedTea IcedTea 2.2.2 IcedTea IcedTea 2.1.2 IBM Rational Service Tester 8.3 IBM Rational Performance Tester 8.3 IBM Rational Host On-Demand 11.0 IBM Rational Host On-Demand 11.0.6.1 IBM Rational Functional Tester 8.3 IBM Rational Functional Tester 8.0 Gentoo Linux |
| Not Vulnerable: |
VMWare vCenter Server 5.1 Update 1 VMWare Update Manager 5.1 Update 1 IcedTea IcedTea 2.3.3 IcedTea IcedTea 2.2.3 IcedTea IcedTea 2.1.3 IBM Rational Service Tester 8.3.0.1 IBM Rational Performance Tester 8.3.0.1 IBM Rational Host On-Demand 11.0.7 IBM Rational Functional Tester 8.3.0.1 |
Discussion
Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'JMX' sub-component.
This vulnerability affects the following supported versions:
7 Update 7
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'JMX' sub-component.
This vulnerability affects the following supported versions:
7 Update 7
Exploit / POC
Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Oracle Java SE CVE-2012-5070 Remote Java Runtime Environment Vulnerability
References:
References:
- [SECURITY] IcedTea 2.1.3, 2.2.3 & 2.3.3 for OpenJDK7 Released! (IcedTea)
- Multiple vulnerabilities fixed in Java 7U9 (Oracle)
- Vulnerabilities in Rational Functional Tester versions 8.x (IBM)
- Oracle Java SE Critical Patch Update Advisory - October 2012 (Oracle)
- Rational Performance Tester: Security Vulnerabilities (IBM)
- Rational Service Tester: Security Vulnerabilities (IBM)
- Security Bulletin: Potential security vulnerabilities in Rational Host On-Demand (IBM)
- Security Bulletin: Vulnerabilities in Rational Functional Tester versions 8.x du (IBM)
- VMSA-2013-0003: VMware vCenter Server, ESXi and ESX security issues. (VMware)
- VMSA-2013-0006 VMware security updates for vCenter Server (VMware)