CVE-2012-4821: Critical severity IBM Java vulnerability

Published Jan 11, 2013
·
Updated

Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.

Affected Software

128 affected components
IBM Java>=1.4.2<=1.4.2.13.13
IBM Java>=5.0.0.0<=5.0.14.0
IBM Java>=6.0.0.0<=6.0.11.0
IBM Java>=7.0.0.0<=7.0.2.0
IBM Lotus Domino=8.0
IBM Lotus Domino=8.0.1
IBM Lotus Domino=8.0.2
IBM Lotus Domino=8.0.2.1
IBM Lotus Domino=8.0.2.2
IBM Lotus Domino=8.0.2.3
IBM Lotus Domino=8.0.2.4
IBM Lotus Domino=8.5.0
IBM Lotus Domino=8.5.0.1
IBM Lotus Domino=8.5.1
IBM Lotus Domino=8.5.1.1
IBM Lotus Domino=8.5.1.2
IBM Lotus Domino=8.5.1.3
IBM Lotus Domino=8.5.1.4
IBM Lotus Domino=8.5.1.5
IBM Lotus Domino=8.5.2.0
IBM Lotus Domino=8.5.2.1
IBM Lotus Domino=8.5.2.2
IBM Lotus Domino=8.5.2.3
IBM Lotus Domino=8.5.2.4
IBM Lotus Domino=8.5.3.0
IBM Lotus Domino=8.5.3.1
IBM Lotus Domino=8.5.3.2
IBM Lotus Notes=8.0
IBM Lotus Notes=8.0.0
IBM Lotus Notes=8.0.1
IBM Lotus Notes=8.0.2
IBM Lotus Notes=8.0.2.0
IBM Lotus Notes=8.0.2.1
IBM Lotus Notes=8.0.2.2
IBM Lotus Notes=8.0.2.3
IBM Lotus Notes=8.0.2.4
IBM Lotus Notes=8.0.2.5
IBM Lotus Notes=8.0.2.6
IBM Lotus Notes=8.5
IBM Lotus Notes=8.5.0.0
IBM Lotus Notes=8.5.0.1
IBM Lotus Notes=8.5.1
IBM Lotus Notes=8.5.1.0
IBM Lotus Notes=8.5.1.1
IBM Lotus Notes=8.5.1.2
IBM Lotus Notes=8.5.1.3
IBM Lotus Notes=8.5.1.4
IBM Lotus Notes=8.5.1.5
IBM Lotus Notes=8.5.2.0
IBM Lotus Notes=8.5.2.1
IBM Lotus Notes=8.5.2.2
IBM Lotus Notes=8.5.2.3
IBM Lotus Notes=8.5.3
IBM Lotus Notes=8.5.3.1
IBM Lotus Notes=8.5.3.2
IBM Lotus Notes=8.5.4
IBM Lotus Notes Sametime=8.0.80407
IBM Lotus Notes Sametime=8.0.80822
IBM Lotus Notes Sametime=8.5.1.20100709-1631
IBM Lotus Notes Traveler=8.0
IBM Lotus Notes Traveler=8.0.1
IBM Lotus Notes Traveler=8.0.1.2
IBM Lotus Notes Traveler=8.0.1.3
IBM Lotus Notes Traveler=8.5.0.0
IBM Lotus Notes Traveler=8.5.0.1
IBM Lotus Notes Traveler=8.5.0.2
IBM Lotus Notes Traveler=8.5.1.1
IBM Lotus Notes Traveler=8.5.1.2
IBM Lotus Notes Traveler=8.5.1.3
IBM Lotus Notes Traveler=8.5.2.1
IBM Lotus Notes Traveler=8.5.3
IBM Lotus Notes Traveler=8.5.3.1
IBM Lotus Notes Traveler=8.5.3.2
IBM Lotus Notes Traveler=8.5.3.3
IBM Lotus Notes Traveler=8.5.3.3-interim_fix_1
IBM Rational Change=4.7
IBM Rational Change=5.1
IBM Rational Change=5.2
IBM Rational Change=5.3
IBM Rational Host On-Demand=1.6.0.12
IBM Rational Host On-Demand=8.0.8.0
IBM Rational Host On-Demand=9.0.8.0
IBM Rational Host On-Demand=10.0.9.0
IBM Rational Host On-Demand=10.0.10.0
IBM Rational Host On-Demand=11.0.3.0
IBM Rational Host On-Demand=11.0.4.0
IBM Rational Host On-Demand=11.0.5.0
IBM Rational Host On-Demand=11.0.5.1
IBM Rational Host On-Demand=11.0.6.0
IBM Rational Host On-Demand=11.0.6.1
IBM Service Delivery Manager=7.2.1.0
IBM Service Delivery Manager=7.2.2.0
IBM Smart Analytics System 5600 Software
IBM Smart Analytics System 5600 Software=9.7
IBM Tivoli Monitoring=6.1.0
IBM Tivoli Monitoring=6.1.0.7
IBM Tivoli Monitoring=6.2.0
IBM Tivoli Monitoring=6.2.0.1
IBM Tivoli Monitoring=6.2.0.2
IBM Tivoli Monitoring=6.2.0.3
IBM Tivoli Monitoring=6.2.1
IBM Tivoli Monitoring=6.2.1.0
IBM Tivoli Monitoring=6.2.1.1
IBM Tivoli Monitoring=6.2.1.2
IBM Tivoli Monitoring=6.2.1.3
IBM Tivoli Monitoring=6.2.1.4
IBM Tivoli Monitoring=6.2.2
IBM Tivoli Monitoring=6.2.2.0
IBM Tivoli Monitoring=6.2.2.1
IBM Tivoli Monitoring=6.2.2.2
IBM Tivoli Monitoring=6.2.2.3
IBM Tivoli Monitoring=6.2.2.4
IBM Tivoli Monitoring=6.2.2.5
IBM Tivoli Monitoring=6.2.2.6
IBM Tivoli Monitoring=6.2.2.7
IBM Tivoli Monitoring=6.2.2.8
IBM Tivoli Monitoring=6.2.2.9
IBM Tivoli Monitoring=6.2.3
IBM Tivoli Monitoring=6.2.3.0
IBM Tivoli Monitoring=6.2.3.1
IBM Tivoli Monitoring=6.2.3.2
IBM Tivoli Remote Control=5.1.2
IBM WebSphere Real Time=2.0
IBM WebSphere Real Time=3.0
Tivoli Storage Productivity Center 5.0
Tivoli Storage Productivity Center 5.1
Tivoli Storage Productivity Center 5.1.1
IBM Smart Analytics System 5600=7200

Event History

Jan 11, 2013
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What versions of IBM software are affected by CVE-2012-4821?

CVE-2012-4821 affects multiple versions of IBM Java, including 7 SR2 and earlier, 6.0.1 SR3 and earlier, 5 SR14 and earlier, and several IBM Lotus and Tivoli products.

2

Is there a patch available to resolve CVE-2012-4821?

Yes, IBM has released updates and patches to address the vulnerabilities associated with CVE-2012-4821.

3

What should I do if I suspect my system is affected by CVE-2012-4821?

You should immediately apply the latest security updates provided by IBM for the affected software versions to mitigate the risks.

4

What kind of vulnerabilities does CVE-2012-4821 encompass?

CVE-2012-4821 includes multiple unspecified vulnerabilities within the IBM Java Runtime Environment that could potentially lead to exploitation.

5

How can I verify if my Java installation is vulnerable to CVE-2012-4821?

You can check the version of your IBM Java installation against the affected versions listed for CVE-2012-4821 to determine if it is vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203