← Vulnerability feed

Vulnerability record · CVE-2012-0500 · published 15 February 2012

CVE-2012-0500: Oracle Java SE Deployment flaw allows untrusted applets to compromise systems

Oracle · Jre

CVE-2012-0500 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier. Because the flaw is unspecified, the exact mechanism is unknown, but it lets remote untrusted Java Web Start applications and untrusted applets affect confidentiality, integrity, and availability. It matters because Java was widely deployed and applet/Web Start execution was a common browser-reachable path.

10.0 CVSS 2.0 High EPSS 59% · top 0.9%
10.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10.0 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus a 99th-percentile EPSS score, make this a top remediation priority despite the lack of confirmed exploitation.

What it is

CVE-2012-0500 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier. Because the flaw is unspecified, the exact mechanism is unknown, but it lets remote untrusted Java Web Start applications and untrusted applets affect confidentiality, integrity, and availability. It matters because Java was widely deployed and applet/Web Start execution was a common browser-reachable path.

Impact

An attacker can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means code execution or equivalent total loss of protection on the host running the vulnerable JRE.

Attack surface

Reached remotely over the network with no authentication, per the AV:N/AC:L/Au:N vector. The description states the attack comes through untrusted Java Web Start applications and untrusted Java applets, so some form of user action to load that content is implied even though the vector does not list user interaction.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high (0.59243, 99th percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Apply the Oracle February 2012 Critical Patch Update or later Java SE/JRE release that fixes CVE-2012-0500, and apply the referenced Red Hat and openSUSE errata on Linux distributions.
  • Upgrade to a supported Java version; Java SE 6 Update 30, 7 Update 2, and JavaFX 2.0.2 and earlier are affected and long out of support.
  • Disable or remove the Java browser plug-in and Java Web Start where not required, and block untrusted applet/Web Start execution.
  • Restrict outbound and inbound Java deployment traffic and enforce allowlisting so untrusted JNLP/applet content cannot be loaded.
  • Where Java is still needed, isolate it in a hardened, non-privileged environment with least-privilege execution.

Detection

  • Monitor for Java Web Start (javaws) and browser plug-in processes spawning unexpected child processes or writing to system directories.
  • Alert on JNLP file downloads and applet loads from untrusted or newly seen hosts, especially outside approved application sources.
  • Inventory endpoints for Java SE 6 Update 30 or earlier, Java SE 7 Update 2 or earlier, and JavaFX 2.0.2 or earlier and flag them for remediation.
  • Review proxy and endpoint logs for Java deployment traffic to low-reputation domains that could deliver malicious applets or JNLP content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-0500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.