CVE-2012-4820
Detail
Deferred
This CVE record is not being prioritized for NVD enrichment efforts due to resource or other concerns.
Description
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://rhn.redhat.com/errata/RHSA-2012-1465.html
CVE, IBM Corporation
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1466.html
CVE, IBM Corporation
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1467.html
CVE, IBM Corporation
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html
CVE, IBM Corporation
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1456.html
CVE, IBM Corporation
Third Party Advisory
http://seclists.org/bugtraq/2012/Sep/38
CVE, IBM Corporation
Mailing List
Third Party Advisory
http://secunia.com/advisories/51326
CVE, IBM Corporation
Third Party Advisory
http://secunia.com/advisories/51327
CVE, IBM Corporation
Third Party Advisory
http://secunia.com/advisories/51328
CVE, IBM Corporation
Third Party Advisory
http://secunia.com/advisories/51393
CVE, IBM Corporation
Third Party Advisory
http://secunia.com/advisories/51634
CVE, IBM Corporation
Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV29654
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21615705
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21615800
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616490
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616594
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616616
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616617
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616652
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21616708
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21621154
CVE, IBM Corporation
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21631786
CVE, IBM Corporation
Vendor Advisory
http://www.securityfocus.com/bid/55495
CVE, IBM Corporation
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/78764
CVE, IBM Corporation
Third Party Advisory
VDB Entry
https://www-304.ibm.com/support/docview.wss?uid=swg21616546
CVE, IBM Corporation
Vendor Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
NVD-CWE-noinfo
Insufficient Information
NIST  
Change History
5 change records found show changes
CVE Modified by CVE 11/20/2024 8:43:33 PM
Action
Type
Old Value
New Value
Added
Reference
http://rhn.redhat.com/errata/RHSA-2012-1465.html
Added
Reference
http://rhn.redhat.com/errata/RHSA-2012-1466.html
Added
Reference
http://rhn.redhat.com/errata/RHSA-2012-1467.html
Added
Reference
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Added
Reference
http://rhn.redhat.com/errata/RHSA-2013-1456.html
Added
Reference
http://seclists.org/bugtraq/2012/Sep/38
Added
Reference
http://secunia.com/advisories/51326
Added
Reference
http://secunia.com/advisories/51327
Added
Reference
http://secunia.com/advisories/51328
Added
Reference
http://secunia.com/advisories/51393
Added
Reference
http://secunia.com/advisories/51634
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg1IV29654
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21615705
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21615800
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616490
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616594
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616616
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616617
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616652
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21616708
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21621154
Added
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21631786
Added
Reference
http://www.securityfocus.com/bid/55495
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/78764
Added
Reference
https://www-304.ibm.com/support/docview.wss?uid=swg21616546
CVE Modified by IBM Corporation 5/13/2024 10:47:07 PM
Action
Type
Old Value
New Value
Modified Analysis by NIST 7/18/2019 8:26:15 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
Record truncated, showing 2048 of 9559 characters.
View Entire Change Record
OR
*cpe:2.3:a:ibm:java:1.4.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.3:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.4:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.5:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.6:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.7:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.8:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.9:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.10:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.11:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:1.4.2.13.12:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions up to (including) 1.4.2.13.13
*cpe:2.3:a:ibm:java:5.0.0.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.11.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.11.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.3:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.4:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.12.5:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:5.0.13.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions up to (including) 5.0.14.0
*cpe:2.3:a:ibm:java:6.0.0.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.1.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.2.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions up to (including) 6.0.3.0
*cpe:2.3:a:ibm:java:6.0.7.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.8.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.8.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.9.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.9.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.9.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.10.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:6.0.10.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions up to (including) 6.0.11.0
*cpe:2.3:a:ibm:java:7.0.0.0:*:*:*:*:
Record truncated, showing 2048 of 7746 characters.
View Entire Change Record
OR
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from (including) 1.4.2 up to (including) 1.4.2.13.13
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from (including) 5.0.0.0 up to (including) 5.0.14.0
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from (including) 6.0.0.0 up to (including) 6.0.11.0
*cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from (including) 7.0.0.0 up to (including) 7.0.2.0
*cpe:2.3:a:ibm:lotus_domino:8.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.2.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.2.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.2.3:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.0.2.4:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.0.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1.3:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1.4:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.1.5:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.2.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.2.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.2.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.2.3:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.2.4:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.3.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.3.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_domino:8.5.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.2:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.2.0:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.2.1:*:*:*:*:*:*:*
*cpe:2.3:a:ibm:lotus_notes:8.0.2.2:*:*:*:*:*:*:*
*cpe:2.3:a:
Changed
Reference Type
http://rhn.redhat.com/errata/RHSA-2012-1465.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2012-1465.html Third Party Advisory
Changed
Reference Type
http://rhn.redhat.com/errata/RHSA-2012-1466.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2012-1466.html Third Party Advisory
Changed
Reference Type
http://rhn.redhat.com/errata/RHSA-2012-1467.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2012-1467.html Third Party Advisory
Changed
Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1455.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
Changed
Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1456.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1456.html Third Party Advisory
Changed
Reference Type
http://seclists.org/bugtraq/2012/Sep/38 No Types Assigned
http://seclists.org/bugtraq/2012/Sep/38 Mailing List, Third Party Advisory
Changed
Reference Type
http://secunia.com/advisories/51326 No Types Assigned
http://secunia.com/advisories/51326 Third Party Advisory
Changed
Reference Type
http://secunia.com/advisories/51327 No Types Assigned
http://secunia.com/advisories/51327 Third Party Advisory
Changed
Reference Type
http://secunia.com/advisories/51328 No Types Assigned
http://secunia.com/advisories/51328 Third Party Advisory
Changed
Reference Type
http://secunia.com/advisories/51393 No Types Assigned
http://secunia.com/advisories/51393 Third Party Advisory
Changed
Reference Type
http://secunia.com/advisories/51634 Vendor Advisory
http://secunia.com/advisories/51634 Third Party Advisory
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21616617 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21616617 Vendor Advisory
Changed
Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21631786 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21631786 Vendor Advisory
Changed
Reference Type
http://www.securityfocus.com/bid/55495 Vendor Advisory
http://www.securityfocus.com/bid/55495 Third Party Advisory, VDB Entry
Changed
Reference Type
https://exchange.xforce.ibmcloud.com/vulnerabilities/78764 No Types Assigned
https://exchange.xforce.ibmcloud.com/vulnerabilities/78764 Third Party Advisory, VDB Entry
CVE Modified by IBM Corporation 8/28/2017 9:32:22 PM
Action
Type
Old Value
New Value
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/78764 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/78764 [No Types Assigned]
Initial CVE Analysis 1/11/2013 9:22:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2012-4820 NVD
Published Date: 01/10/2013 NVD
Last Modified: 04/10/2025
Source: IBM Corporation