Description
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."
Published: 2013-01-11
Score: 9.3 Critical
EPSS: 9.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2012-4745 Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."
History

No history.

Subscriptions

Ibm Java Lotus Domino Lotus Notes Lotus Notes Sametime Lotus Notes Traveler Rational Change Rational Host On-demand Service Delivery Manager Smart Analytics System 5600 Smart Analytics System 5600 Software Tivoli Monitoring Tivoli Remote Control Websphere Real Time
Redhat Network Satellite Rhel Extras
Tivoli Storage Productivity Center 5.0 5.1 5.1.1
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-06T20:50:17.367Z

Reserved: 2012-09-06T00:00:00.000Z

Link: CVE-2012-4820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-01-11T00:55:00.963

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-4820

cve-icon Redhat

Severity : Important

Publid Date: 2012-11-13T00:00:00Z

Links: CVE-2012-4820 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses