CVE-2012-1723
A critical flaw in Oracle Java SE allows attackers to compromise the confidentiality, integrity, and availability of systems that run vulnerable Java versions. The vulnerability can be triggered remotely without any user interaction. Updating to a patched Java release removes the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier.
Real-world impact
An attacker could read, modify, or delete data, disrupt services, or take full control of affected systems.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited over the network with no authentication, no user interaction, and it can fully compromise confidentiality, integrity, and availability.
What to do about it
- 01Update Oracle Java SE to the latest available version for your platform.
- 02Restart any Java applications or services to ensure the update takes effect.
CISA KEV required action
Timeline
- Jun 16, 2012 · Jun 16, 2012PublishedDisclosed and added to the National Vulnerability Database.
- Mar 3, 2022 · Mar 3, 2022Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Mar 24, 2022 · Mar 24, 2022CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Aug 6, 2026 · 4h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- mail.openjdk.java.net/pipermail/distro-pkg-dev/20…mailing list
- marc.infomailing list
- rhn.redhat.com/errata/RHSA-2012-0734.htmlthird party advisory
- secunia.com/advisories/51080broken link
- security.gentoo.org/glsa/glsa-201406-32.xmlthird party advisory
- ibm.com/support/docview.wssbroken link
- mandriva.com/security/advisoriesbroken link
- oracle.com/technetwork/topics/security…vendor advisory
- securityfocus.com/bid/53960broken linkthird party advisoryvdb entry
- oval.cisecurity.org/repository/search/definitio…broken link
- cisa.gov/known-exploited-vulnerabili…us government resource