CVE-2012-0547

Oracle Java SE <7.6 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0547.

AI-analyzed exploit summary This Metasploit module exploits a Java 7 vulnerability (CVE-2012-0547) to achieve remote code execution by delivering a malicious JAR file via an HTML page with an embedded applet. The exploit bypasses the Java sandbox and has been tested against multiple browsers and platforms.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

Exploits (1)

exploitdb WORKING POC
rubyremotejava
https://www.exploit-db.com/exploits/20865

This Metasploit module exploits a Java 7 vulnerability (CVE-2012-0547) to achieve remote code execution by delivering a malicious JAR file via an HTML page with an embedded applet. The exploit bypasses the Java sandbox and has been tested against multiple browsers and platforms.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java 7 (JRE 1.7)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Java 7 must be installed and enabled in the browser
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (19)

Core 19
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=135161897205627&w=2
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1222.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1553-1
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1466.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51141
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/55339
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1392.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1225.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51327
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51044
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1456.html

Scores

EPSS 0.0854
EPSS Percentile 92.6%

Details

Status published
Products (8)
oracle/jdk 1.7.0 (7 CPE variants)
oracle/jdk 1.6.0 update22 (11 CPE variants)
oracle/jdk < 1.6.0
oracle/jre 1.7.0 (6 CPE variants)
oracle/jre 1.6.0 update22 (12 CPE variants)
oracle/jre < 1.6.0
oracle/jre < 1.7.0
sun/jdk 1.6.0 update_10 (11 CPE variants)
Published Aug 30, 2012
Tracked Since Feb 18, 2026