Vulnerability record · CVE-2012-5067 · published 16 October 2012
CVE-2012-5067: Oracle Java SE JRE Deployment component confidentiality flaw
Oracle · Jdk
CVE-2012-5067 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 7 and earlier. Oracle's advisory and the NVD entry give no detail on the underlying defect, so the exact mechanism is unknown. It matters because it is remotely reachable without authentication and can expose confidential data.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityRemote unauthenticated confidentiality impact and very high EPSS, but only partial confidentiality loss, no integrity or availability effect, and no confirmed exploitation or KEV listing.
What it is
CVE-2012-5067 is an unspecified vulnerability in the Deployment component of Oracle Java SE 7 Update 7 and earlier. Oracle's advisory and the NVD entry give no detail on the underlying defect, so the exact mechanism is unknown. It matters because it is remotely reachable without authentication and can expose confidential data.
Impact
An attacker can read data the JRE would otherwise protect; the CVSS 2.0 vector rates only partial confidentiality impact, with no integrity or availability effect.
Attack surface
Network-reachable (AV:N) with low complexity and no authentication (Au:N) per the CVSS vector; the description names the Deployment component, which in Java SE is the web-start and applet launch path, so a user likely has to load attacker-supplied Java content, though the record does not state this explicitly.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.63983 (99.18th percentile), indicating high predicted exploitation activity despite the absence of confirmed in-the-wild reporting.
What to do
- Upgrade to a Java SE release after 7 Update 7, applying the October 2012 Oracle Critical Patch Update or later
- Apply the referenced Red Hat and openSUSE errata if running the distribution-packaged JDK/JRE
- Disable or restrict Java browser plug-in and web-start deployment where not required
- Remove unsupported Java versions from endpoints and enforce a minimum patched baseline
Detection
- Inventory endpoints for Java SE 7 Update 7 and earlier via installed-version checks
- Monitor for Java web-start or applet launches from untrusted or unusual origins
- Alert on JRE processes making unexpected outbound network connections after loading Java content
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5067 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5067), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.