vendor:
Java Runtime Environment
by:
sinn3r, juan vazquez, egypt
N/A
CVSS
N/A
Type Violation
843
CWE
Product Name: Java Runtime Environment
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2012-0507
CPE: Unknown
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1455/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0013-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/jre-vuln-cve-2012-0507/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0514/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0508/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-3571/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-3571/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-3571/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac, Solaris
2012
Java AtomicReferenceArray Type Violation Vulnerability
This module exploits a vulnerability due to the fact that AtomicReferenceArray uses the Unsafe class to store a reference in an array directly, which may violate type safety if not used properly. This allows a way to escape the JRE sandbox, and load additional classes in order to perform malicious operations.
Mitigation:
Update to the latest version of Java Runtime Environment