CVE Feed

    Dashboard / CVE / CVE-2012-4820

    CVE-2012-4820

    Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

    Published:Nov 13, 2012
    Last Modified:Apr 11, 2025
    EPS:Jan 11, 2013
    EPSS Score:0.09366
    CVSS Score:9.3

    Affected Products

    Vendor
    Ibm
    Product
    Java
    Vendor
    Ibm
    Product
    Lotus Domino
    Vendor
    Ibm
    Product
    Lotus Notes
    Vendor
    Ibm
    Product
    Lotus Notes Sametime
    Vendor
    Ibm
    Product
    Lotus Notes Traveler
    Vendor
    Ibm
    Product
    Rational Change
    Vendor
    Ibm
    Product
    Rational Host On-demand
    Vendor
    Ibm
    Product
    Service Delivery Manager
    Vendor
    Ibm
    Product
    Smart Analytics System 5600
    Vendor
    Ibm
    Product
    Smart Analytics System 5600 Software
    Vendor
    Ibm
    Product
    Tivoli Monitoring
    Vendor
    Ibm
    Product
    Tivoli Remote Control
    Vendor
    Ibm
    Product
    Websphere Real Time
    Vendor
    Redhat
    Product
    Network Satellite
    Vendor
    Redhat
    Product
    Rhel Extras
    Vendor
    Tivoli Storage Productivity Center
    Product
    5.0
    Vendor
    Tivoli Storage Productivity Center
    Product
    5.1
    Vendor
    Tivoli Storage Productivity Center
    Product
    5.1.1

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High