Vulnerability record · CVE-2012-5076 · published 16 October 2012
CVE-2012-5076: Oracle Java SE JRE JAX-WS sandbox bypass
Oracle · Jre
CVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JAX-WS. It allows remote attackers to affect confidentiality, integrity, and availability, and CISA classifies it as a Java SE sandbox bypass. Because the flaw is unspecified, the exact mechanism is not documented in this record.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, and a 0.91 EPSS probability indicate active exploitation and severe impact, though the underlying flaw is unspecified.
What it is
CVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JAX-WS. It allows remote attackers to affect confidentiality, integrity, and availability, and CISA classifies it as a Java SE sandbox bypass. Because the flaw is unspecified, the exact mechanism is not documented in this record.
Impact
An attacker can compromise confidentiality, integrity, and availability of the affected system, and as a sandbox bypass it can allow code to escape Java's security restrictions. Successful exploitation could lead to arbitrary code execution in the context of the JRE process.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so it can be triggered remotely over the network. The description does not state whether a crafted web page, applet, or JAX-WS service request is the delivery path.
Exploitation
CVE-2012-5076 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), indicating exploitation in the wild, and EPSS gives a 30-day probability of 0.91013 (99.8th percentile). No ransomware campaign use is documented.
What to do
- Apply the Oracle October 2012 Critical Patch Update or later for Java SE, per the vendor advisory.
- Apply the referenced Red Hat, openSUSE, and Gentoo errata for affected Linux distributions.
- Remove or disable Java browser plug-ins and applets where they are not required.
- Upgrade to a supported Java SE release; Java SE 7 Update 7 and earlier are long out of support.
- Restrict network exposure of JAX-WS services and Java-based endpoints to trusted clients.
Detection
- Monitor for Java processes spawning unexpected child processes or making anomalous outbound network connections.
- Alert on JAX-WS or Java web service requests from untrusted sources to Java endpoints.
- Inventory hosts still running Java SE 7 Update 7 or earlier and flag them for remediation.
- Review application and system logs for Java security exceptions or sandbox-related errors preceding suspicious activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-5076 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Java SE Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5076 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.