First published: Fri Jan 11 2013(Updated: )
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK | >=1.4.2<=1.4.2.13.13 | |
IBM JDK | >=5.0.0.0<=5.0.14.0 | |
IBM JDK | >=6.0.0.0<=6.0.11.0 | |
IBM JDK | >=7.0.0.0<=7.0.2.0 | |
IBM Lotus Domino | =8.0 | |
IBM Lotus Domino | =8.0.1 | |
IBM Lotus Domino | =8.0.2 | |
IBM Lotus Domino | =8.0.2.1 | |
IBM Lotus Domino | =8.0.2.2 | |
IBM Lotus Domino | =8.0.2.3 | |
IBM Lotus Domino | =8.0.2.4 | |
IBM Lotus Domino | =8.5.0 | |
IBM Lotus Domino | =8.5.0.1 | |
IBM Lotus Domino | =8.5.1 | |
IBM Lotus Domino | =8.5.1.1 | |
IBM Lotus Domino | =8.5.1.2 | |
IBM Lotus Domino | =8.5.1.3 | |
IBM Lotus Domino | =8.5.1.4 | |
IBM Lotus Domino | =8.5.1.5 | |
IBM Lotus Domino | =8.5.2.0 | |
IBM Lotus Domino | =8.5.2.1 | |
IBM Lotus Domino | =8.5.2.2 | |
IBM Lotus Domino | =8.5.2.3 | |
IBM Lotus Domino | =8.5.2.4 | |
IBM Lotus Domino | =8.5.3.0 | |
IBM Lotus Domino | =8.5.3.1 | |
IBM Lotus Domino | =8.5.3.2 | |
IBM Lotus Notes | =8.0 | |
IBM Lotus Notes | =8.0.0 | |
IBM Lotus Notes | =8.0.1 | |
IBM Lotus Notes | =8.0.2 | |
IBM Lotus Notes | =8.0.2.0 | |
IBM Lotus Notes | =8.0.2.1 | |
IBM Lotus Notes | =8.0.2.2 | |
IBM Lotus Notes | =8.0.2.3 | |
IBM Lotus Notes | =8.0.2.4 | |
IBM Lotus Notes | =8.0.2.5 | |
IBM Lotus Notes | =8.0.2.6 | |
IBM Lotus Notes | =8.5 | |
IBM Lotus Notes | =8.5.0.0 | |
IBM Lotus Notes | =8.5.0.1 | |
IBM Lotus Notes | =8.5.1 | |
IBM Lotus Notes | =8.5.1.0 | |
IBM Lotus Notes | =8.5.1.1 | |
IBM Lotus Notes | =8.5.1.2 | |
IBM Lotus Notes | =8.5.1.3 | |
IBM Lotus Notes | =8.5.1.4 | |
IBM Lotus Notes | =8.5.1.5 | |
IBM Lotus Notes | =8.5.2.0 | |
IBM Lotus Notes | =8.5.2.1 | |
IBM Lotus Notes | =8.5.2.2 | |
IBM Lotus Notes | =8.5.2.3 | |
IBM Lotus Notes | =8.5.3 | |
IBM Lotus Notes | =8.5.3.1 | |
IBM Lotus Notes | =8.5.3.2 | |
IBM Lotus Notes | =8.5.4 | |
HCL Sametime | =8.0.80407 | |
HCL Sametime | =8.0.80822 | |
HCL Sametime | =8.5.1.20100709-1631 | |
IBM Notes Traveler | =8.0 | |
IBM Notes Traveler | =8.0.1 | |
IBM Notes Traveler | =8.0.1.2 | |
IBM Notes Traveler | =8.0.1.3 | |
IBM Notes Traveler | =8.5.0.0 | |
IBM Notes Traveler | =8.5.0.1 | |
IBM Notes Traveler | =8.5.0.2 | |
IBM Notes Traveler | =8.5.1.1 | |
IBM Notes Traveler | =8.5.1.2 | |
IBM Notes Traveler | =8.5.1.3 | |
IBM Notes Traveler | =8.5.2.1 | |
IBM Notes Traveler | =8.5.3 | |
IBM Notes Traveler | =8.5.3.1 | |
IBM Notes Traveler | =8.5.3.2 | |
IBM Notes Traveler | =8.5.3.3 | |
IBM Notes Traveler | =8.5.3.3-interim_fix_1 | |
IBM Rational Change | =4.7 | |
IBM Rational Change | =5.1 | |
IBM Rational Change | =5.2 | |
IBM Rational Change | =5.3 | |
IBM Rational Host On-Demand | =1.6.0.12 | |
IBM Rational Host On-Demand | =8.0.8.0 | |
IBM Rational Host On-Demand | =9.0.8.0 | |
IBM Rational Host On-Demand | =10.0.9.0 | |
IBM Rational Host On-Demand | =10.0.10.0 | |
IBM Rational Host On-Demand | =11.0.3.0 | |
IBM Rational Host On-Demand | =11.0.4.0 | |
IBM Rational Host On-Demand | =11.0.5.0 | |
IBM Rational Host On-Demand | =11.0.5.1 | |
IBM Rational Host On-Demand | =11.0.6.0 | |
IBM Rational Host On-Demand | =11.0.6.1 | |
Ibm Service Delivery Manager | =7.2.1.0 | |
Ibm Service Delivery Manager | =7.2.2.0 | |
Ibm Smart Analytics System 5600 Software | ||
Ibm Smart Analytics System 5600 Software | =9.7 | |
IBM Tivoli Monitoring | =6.1.0 | |
IBM Tivoli Monitoring | =6.1.0.7 | |
IBM Tivoli Monitoring | =6.2.0 | |
IBM Tivoli Monitoring | =6.2.0.1 | |
IBM Tivoli Monitoring | =6.2.0.2 | |
IBM Tivoli Monitoring | =6.2.0.3 | |
IBM Tivoli Monitoring | =6.2.1 | |
IBM Tivoli Monitoring | =6.2.1.0 | |
IBM Tivoli Monitoring | =6.2.1.1 | |
IBM Tivoli Monitoring | =6.2.1.2 | |
IBM Tivoli Monitoring | =6.2.1.3 | |
IBM Tivoli Monitoring | =6.2.1.4 | |
IBM Tivoli Monitoring | =6.2.2 | |
IBM Tivoli Monitoring | =6.2.2.0 | |
IBM Tivoli Monitoring | =6.2.2.1 | |
IBM Tivoli Monitoring | =6.2.2.2 | |
IBM Tivoli Monitoring | =6.2.2.3 | |
IBM Tivoli Monitoring | =6.2.2.4 | |
IBM Tivoli Monitoring | =6.2.2.5 | |
IBM Tivoli Monitoring | =6.2.2.6 | |
IBM Tivoli Monitoring | =6.2.2.7 | |
IBM Tivoli Monitoring | =6.2.2.8 | |
IBM Tivoli Monitoring | =6.2.2.9 | |
IBM Tivoli Monitoring | =6.2.3 | |
IBM Tivoli Monitoring | =6.2.3.0 | |
IBM Tivoli Monitoring | =6.2.3.1 | |
IBM Tivoli Monitoring | =6.2.3.2 | |
IBM Tivoli Remote Control | =5.1.2 | |
IBM WebSphere Real Time | =2.0 | |
IBM WebSphere Real Time | =3.0 | |
Tivoli Storage Productivity Center 5.0 | ||
Tivoli Storage Productivity Center 5.1 | ||
Tivoli Storage Productivity Center 5.1.1 | ||
Ibm Smart Analytics System 5600 | =7200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4821 affects multiple versions of IBM Java, including 7 SR2 and earlier, 6.0.1 SR3 and earlier, 5 SR14 and earlier, and several IBM Lotus and Tivoli products.
Yes, IBM has released updates and patches to address the vulnerabilities associated with CVE-2012-4821.
You should immediately apply the latest security updates provided by IBM for the affected software versions to mitigate the risks.
CVE-2012-4821 includes multiple unspecified vulnerabilities within the IBM Java Runtime Environment that could potentially lead to exploitation.
You can check the version of your IBM Java installation against the affected versions listed for CVE-2012-4821 to determine if it is vulnerable.