← Vulnerability feed

Vulnerability record · CVE-2012-5081 · published 16 October 2012

CVE-2012-5081: Oracle Java JRE JSSE flaw allows remote denial of service

Oracle · Jdk

CVE-2012-5081 is an unspecified vulnerability in the JSSE component of Oracle Java SE (JRE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier). The record gives no root-cause detail beyond the JSSE reference, but the CVSS vector shows a remote, unauthenticated attacker can degrade availability. Because Java is widely deployed and the flaw is remotely reachable, unpatched hosts remain exposed to denial of service.

5.0 CVSS 2.0 Medium EPSS 45% · top 1.3%
5.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
78References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to JSSE.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityRemote unauthenticated availability impact with high EPSS but no KEV listing or confirmed exploitation, and the affected Java versions are very old.

What it is

CVE-2012-5081 is an unspecified vulnerability in the JSSE component of Oracle Java SE (JRE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier). The record gives no root-cause detail beyond the JSSE reference, but the CVSS vector shows a remote, unauthenticated attacker can degrade availability. Because Java is widely deployed and the flaw is remotely reachable, unpatched hosts remain exposed to denial of service.

Impact

An attacker can affect availability of the Java runtime, causing a denial of service. There is no confidentiality or integrity impact per the CVSS vector.

Attack surface

Reachable over the network (AV:N) with low complexity and no authentication (AC:L/Au:N), consistent with a remotely triggerable JSSE issue. The record does not state whether user interaction is required.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.45113, 98.7th percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Apply the Oracle Java SE CPU update that addresses CVE-2012-5081, or the corresponding Red Hat and openSUSE errata listed in the references.
  • Upgrade to a supported Java release; the affected 1.4.2, 5.0, 6 and 7 Update 7 and earlier lines are long end-of-life.
  • Remove or disable Java browser and JSSE-dependent components on systems that do not require them.
  • Restrict outbound and inbound network access to Java/JSSE services to trusted hosts only.
  • Inventory Java versions across servers and endpoints and prioritize internet-facing or shared instances for patching.

Detection

  • Monitor for abnormal JVM crashes, hangs or restarts that coincide with inbound network connections to Java services.
  • Alert on Java processes spawning unexpectedly or terminating abnormally on hosts running the affected versions.
  • Track Java version inventory and flag any host still running JRE 7 Update 7 or earlier, 6 Update 35 or earlier, 5.0 Update 36 or earlier, or 1.4.2_38 or earlier.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00022.html
http://marc.info/?l=bugtraq&m=135542848327757&w=2
http://marc.info/?l=bugtraq&m=135758563611658&w=2
http://rhn.redhat.com/errata/RHSA-2012-1385.html
http://rhn.redhat.com/errata/RHSA-2012-1386.html
http://rhn.redhat.com/errata/RHSA-2012-1391.html
http://rhn.redhat.com/errata/RHSA-2012-1392.html
http://rhn.redhat.com/errata/RHSA-2012-1465.html
http://rhn.redhat.com/errata/RHSA-2012-1466.html
http://rhn.redhat.com/errata/RHSA-2012-1467.html
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://secunia.com/advisories/51028
http://secunia.com/advisories/51029
http://secunia.com/advisories/51141
http://secunia.com/advisories/51166
http://secunia.com/advisories/51313
http://secunia.com/advisories/51315
http://secunia.com/advisories/51326
http://secunia.com/advisories/51327
http://secunia.com/advisories/51328
http://secunia.com/advisories/51390
http://secunia.com/advisories/51393
http://secunia.com/advisories/51438
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www-01.ibm.com/support/docview.wss?uid=swg21620037
http://www-01.ibm.com/support/docview.wss?uid=swg21620575
http://www-01.ibm.com/support/docview.wss?uid=swg21631786
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-023/index.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html PatchVendor Advisory
http://www.securityfocus.com/bid/56071
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16043
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html

Track CVE-2012-5081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5081), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.