HIGH · 9.3

CVE-2012-4823

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used ...

Vulnerability Description

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
IbmJava>= 1.4.2, <= 1.4.2.13.13
IbmLotus Domino8.0
IbmLotus Notes8.0
IbmLotus Notes Sametime8.0.80407
IbmLotus Notes Traveler8.0
IbmRational Change4.7
IbmRational Host On-Demand1.6.0.12
IbmService Delivery Manager7.2.1.0
IbmSmart Analytics System 5600 Software-
IbmTivoli Monitoring6.1.0
IbmTivoli Remote Control5.1.2
IbmWebsphere Real Time2.0
Tivoli Storage Productivity Center5.0All versions
Tivoli Storage Productivity Center5.1All versions
Tivoli Storage Productivity Center5.1.1All versions
IbmSmart Analytics System 56007200

References

FAQ

What is CVE-2012-4823?

CVE-2012-4823 is a vulnerability with a CVSS score of 9.3 (HIGH). Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used ...

How severe is CVE-2012-4823?

CVE-2012-4823 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4823?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Java, Ibm Lotus Domino, Ibm Lotus Notes, Ibm Lotus Notes Sametime, Ibm Lotus Notes Traveler.