Vulnerability record · CVE-2012-5081 · published 16 October 2012
CVE-2012-5081: Oracle Java JRE JSSE flaw allows remote denial of service
Oracle · Jdk
CVE-2012-5081 is an unspecified vulnerability in the JSSE component of Oracle Java SE (JRE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier). The record gives no root-cause detail beyond the JSSE reference, but the CVSS vector shows a remote, unauthenticated attacker can degrade availability. Because Java is widely deployed and the flaw is remotely reachable, unpatched hosts remain exposed to denial of service.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to JSSE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated availability impact with high EPSS but no KEV listing or confirmed exploitation, and the affected Java versions are very old.
What it is
CVE-2012-5081 is an unspecified vulnerability in the JSSE component of Oracle Java SE (JRE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier). The record gives no root-cause detail beyond the JSSE reference, but the CVSS vector shows a remote, unauthenticated attacker can degrade availability. Because Java is widely deployed and the flaw is remotely reachable, unpatched hosts remain exposed to denial of service.
Impact
An attacker can affect availability of the Java runtime, causing a denial of service. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with low complexity and no authentication (AC:L/Au:N), consistent with a remotely triggerable JSSE issue. The record does not state whether user interaction is required.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.45113, 98.7th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Apply the Oracle Java SE CPU update that addresses CVE-2012-5081, or the corresponding Red Hat and openSUSE errata listed in the references.
- Upgrade to a supported Java release; the affected 1.4.2, 5.0, 6 and 7 Update 7 and earlier lines are long end-of-life.
- Remove or disable Java browser and JSSE-dependent components on systems that do not require them.
- Restrict outbound and inbound network access to Java/JSSE services to trusted hosts only.
- Inventory Java versions across servers and endpoints and prioritize internet-facing or shared instances for patching.
Detection
- Monitor for abnormal JVM crashes, hangs or restarts that coincide with inbound network connections to Java services.
- Alert on Java processes spawning unexpectedly or terminating abnormally on hosts running the affected versions.
- Track Java version inventory and flag any host still running JRE 7 Update 7 or earlier, 6 Update 35 or earlier, 5.0 Update 36 or earlier, or 1.4.2_38 or earlier.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5081), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.