← Vulnerability feed

Vulnerability record · CVE-2012-5088 · published 16 October 2012

CVE-2012-5088: Oracle Java SE JRE Libraries unspecified remote code execution flaw

Oracle · Jre

CVE-2012-5088 is an unspecified vulnerability in the Libraries component of Oracle Java SE 7 Update 7 and earlier. The description gives no root cause, affected class, or attack vector detail, but the CVSS 2.0 vector rates it 10.0 with complete confidentiality, integrity, and availability impact. Because the flaw is in the JRE and reachable over the network without authentication, it matters as a potential full-compromise issue for any host running the affected Java version.

10.0 CVSS 2.0 High EPSS 79% · top 0.4%
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and complete impact on confidentiality, integrity, and availability, combined with a very high EPSS percentile, warrants critical treatment despite the thin description.

What it is

CVE-2012-5088 is an unspecified vulnerability in the Libraries component of Oracle Java SE 7 Update 7 and earlier. The description gives no root cause, affected class, or attack vector detail, but the CVSS 2.0 vector rates it 10.0 with complete confidentiality, integrity, and availability impact. Because the flaw is in the JRE and reachable over the network without authentication, it matters as a potential full-compromise issue for any host running the affected Java version.

Impact

A remote attacker can fully compromise confidentiality, integrity, and availability of the affected Java process and, depending on the host context, the underlying system. The record does not specify whether code execution, sandbox escape, or another outcome is achieved.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates network reachability with no authentication and low complexity. The description says only 'unknown vectors related to Libraries', so the exact entry point (for example, a Java applet, Web Start application, or server-side deserialization) is not stated; user interaction is not specified.

Exploitation

CVE-2012-5088 is not listed in CISA KEV and has no ransomware associations in the record. EPSS gives a 30-day exploitation probability of 0.78696 (99.568th percentile), indicating a high modeled likelihood, but the references carry no exploit tags and no public exploit is confirmed by this data.

What to do

  • Upgrade Oracle Java SE to a version after 7 Update 7, or apply the October 2012 Oracle Critical Patch Update referenced in the vendor advisory.
  • Apply the corresponding Red Hat and openSUSE errata for any distribution-packaged JRE/JDK.
  • If Java is not required, remove or disable the JRE/JDK on affected hosts.
  • Where Java is required, restrict browser and network access to untrusted Java content and disable the Java browser plug-in.
  • Inventory hosts still running Java SE 7 Update 7 or earlier and prioritize them for remediation.

Detection

  • Inventory installed Java versions and flag any JRE/JDK at 7 Update 7 or earlier.
  • Monitor for Java processes spawning unexpected child processes or making anomalous outbound network connections.
  • Review proxy, DNS, and firewall logs for Java clients retrieving JAR or applet content from untrusted external hosts.
  • Check host logs for crashes or abnormal behavior in java.exe/javaw processes on systems running the affected version.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5088 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5088), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.