CISA Known Exploited Vulnerability

CVE-2012-5076

Oracle · Java SE

Oracle Java SE Sandbox Bypass Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

Required action

Apply updates per vendor instructions.