← Vulnerability feed

Vulnerability record · CVE-2012-5076 · published 16 October 2012

CVE-2012-5076: Oracle Java SE JRE JAX-WS sandbox bypass

Oracle · Jre

CVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JAX-WS. It allows remote attackers to affect confidentiality, integrity, and availability, and CISA classifies it as a Java SE sandbox bypass. Because the flaw is unspecified, the exact mechanism is not documented in this record.

9.8 CVSS 3.1 Critical CISA KEV since 28 Mar 2022 EPSS 91% · top 0.2% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 10.0
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
21References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8, CISA KEV listing, and a 0.91 EPSS probability indicate active exploitation and severe impact, though the underlying flaw is unspecified.

What it is

CVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JAX-WS. It allows remote attackers to affect confidentiality, integrity, and availability, and CISA classifies it as a Java SE sandbox bypass. Because the flaw is unspecified, the exact mechanism is not documented in this record.

Impact

An attacker can compromise confidentiality, integrity, and availability of the affected system, and as a sandbox bypass it can allow code to escape Java's security restrictions. Successful exploitation could lead to arbitrary code execution in the context of the JRE process.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so it can be triggered remotely over the network. The description does not state whether a crafted web page, applet, or JAX-WS service request is the delivery path.

Exploitation

CVE-2012-5076 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), indicating exploitation in the wild, and EPSS gives a 30-day probability of 0.91013 (99.8th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Oracle October 2012 Critical Patch Update or later for Java SE, per the vendor advisory.
  • Apply the referenced Red Hat, openSUSE, and Gentoo errata for affected Linux distributions.
  • Remove or disable Java browser plug-ins and applets where they are not required.
  • Upgrade to a supported Java SE release; Java SE 7 Update 7 and earlier are long out of support.
  • Restrict network exposure of JAX-WS services and Java-based endpoints to trusted clients.

Detection

  • Monitor for Java processes spawning unexpected child processes or making anomalous outbound network connections.
  • Alert on JAX-WS or Java web service requests from untrusted sources to Java endpoints.
  • Inventory hosts still running Java SE 7 Update 7 or earlier and flag them for remediation.
  • Review application and system logs for Java security exceptions or sandbox-related errors preceding suspicious activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2012-5076 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Java SE Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1386.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1391.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1467.html Third Party Advisory
http://secunia.com/advisories/51029 Not Applicable
http://secunia.com/advisories/51326 Not Applicable
http://secunia.com/advisories/51390 Not Applicable
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16641 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1386.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1391.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1467.html Third Party Advisory
http://secunia.com/advisories/51029 Not Applicable
http://secunia.com/advisories/51326 Not Applicable
http://secunia.com/advisories/51390 Not Applicable
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16641 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-5076 US Government Resource

Track CVE-2012-5076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.