← KEV catalog
CISA known exploited vulnerability

CVE-2012-5076

Oracle Java SE Sandbox Bypass Vulnerability

SOURCE FACT

Oracle · Java SE

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2012-5076

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?