Vulnerability record · CVE-2012-5088 · published 16 October 2012
CVE-2012-5088: Oracle Java SE JRE Libraries unspecified remote code execution flaw
Oracle · Jre
CVE-2012-5088 is an unspecified vulnerability in the Libraries component of Oracle Java SE 7 Update 7 and earlier. The description gives no root cause, affected class, or attack vector detail, but the CVSS 2.0 vector rates it 10.0 with complete confidentiality, integrity, and availability impact. Because the flaw is in the JRE and reachable over the network without authentication, it matters as a potential full-compromise issue for any host running the affected Java version.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and complete impact on confidentiality, integrity, and availability, combined with a very high EPSS percentile, warrants critical treatment despite the thin description.
What it is
CVE-2012-5088 is an unspecified vulnerability in the Libraries component of Oracle Java SE 7 Update 7 and earlier. The description gives no root cause, affected class, or attack vector detail, but the CVSS 2.0 vector rates it 10.0 with complete confidentiality, integrity, and availability impact. Because the flaw is in the JRE and reachable over the network without authentication, it matters as a potential full-compromise issue for any host running the affected Java version.
Impact
A remote attacker can fully compromise confidentiality, integrity, and availability of the affected Java process and, depending on the host context, the underlying system. The record does not specify whether code execution, sandbox escape, or another outcome is achieved.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates network reachability with no authentication and low complexity. The description says only 'unknown vectors related to Libraries', so the exact entry point (for example, a Java applet, Web Start application, or server-side deserialization) is not stated; user interaction is not specified.
Exploitation
CVE-2012-5088 is not listed in CISA KEV and has no ransomware associations in the record. EPSS gives a 30-day exploitation probability of 0.78696 (99.568th percentile), indicating a high modeled likelihood, but the references carry no exploit tags and no public exploit is confirmed by this data.
What to do
- Upgrade Oracle Java SE to a version after 7 Update 7, or apply the October 2012 Oracle Critical Patch Update referenced in the vendor advisory.
- Apply the corresponding Red Hat and openSUSE errata for any distribution-packaged JRE/JDK.
- If Java is not required, remove or disable the JRE/JDK on affected hosts.
- Where Java is required, restrict browser and network access to untrusted Java content and disable the Java browser plug-in.
- Inventory hosts still running Java SE 7 Update 7 or earlier and prioritize them for remediation.
Detection
- Inventory installed Java versions and flag any JRE/JDK at 7 Update 7 or earlier.
- Monitor for Java processes spawning unexpected child processes or making anomalous outbound network connections.
- Review proxy, DNS, and firewall logs for Java clients retrieving JAR or applet content from untrusted external hosts.
- Check host logs for crashes or abnormal behavior in java.exe/javaw processes on systems running the affected version.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5088 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5088), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.