CVE-2012-4823
IBM Java < 1.4.2.13.13 - Remote Code Execution via Insecure ClassLoader defineClass()
Title source: llmDescription
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."
References (21)
Core 21
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21621154
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616652
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55495
Vendor Advisory x_refsource_confirm
https://www-304.ibm.com/support/docview.wss?uid=swg21616546
VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78767
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616708
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1466.html
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616616
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616594
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616617
Mailing List, Third Party Advisory mailing-list
x_refsource_bugtraq
http://seclists.org/bugtraq/2012/Sep/38
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV29687
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21615800
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21616490
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/51327
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1467.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/51634
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21615705
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1456.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/51326
Scores
EPSS
0.0686
EPSS Percentile
93.4%
Details
Status
published
Products (50)
ibm/java
1.4.2 - 1.4.2.13.13
ibm/lotus_domino
8.0
ibm/lotus_domino
8.0.1
ibm/lotus_domino
8.0.2
ibm/lotus_domino
8.0.2.1
ibm/lotus_domino
8.0.2.2
ibm/lotus_domino
8.0.2.3
ibm/lotus_domino
8.0.2.4
ibm/lotus_domino
8.5.0
ibm/lotus_domino
8.5.0.1
... and 40 more
Published
Jan 11, 2013
Tracked Since
Feb 18, 2026