OpenJDK: AtomicReferenceArray insufficient array type check (Concurrency, 7082299)
Published Jun 7, 2012 ·Due Mar 24, 2022
9.8
CRITICALCVSS 3.1
EPSS 98.11%
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Affected products
No data.
Configuration 1
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 2
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 3
Configuration 4
- 6.0
- 7.0
Configuration 5
- 10
- 10
- 11
- 10
- 11
- 11
- 11
- 11
- 11
No data.
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.25.1.10.6.el5_8
Fixed · RHSA-2012:0322
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.43.1.10.6.el6_2
Fixed · RHSA-2012:0135
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
Fixed · RHSA-2013:1455
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5
Fixed · RHSA-2012:0508
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.10.1-1jpp.1.el5
Fixed · RHSA-2012:0514
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.31-1jpp.1.el5
Fixed · RHSA-2012:0139
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2
Fixed · RHSA-2012:0508
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.10.1-1jpp.5.el6_2
Fixed · RHSA-2012:0514
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.31-1jpp.1.el6_2
Fixed · RHSA-2012:0139
Red Hat Enterprise Linux 4
java-1.6.0-sun
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.25.1.10.6.el5_8 | Fixed | RHSA-2012:0322 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.43.1.10.6.el6_2 | Fixed | RHSA-2012:0135 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 | Fixed | RHSA-2013:1455 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.13.1-1jpp.1.el5 | Fixed | RHSA-2012:0508 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.10.1-1jpp.1.el5 | Fixed | RHSA-2012:0514 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.31-1jpp.1.el5 | Fixed | RHSA-2012:0139 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.13.1-1jpp.2.el6_2 | Fixed | RHSA-2012:0508 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.10.1-1jpp.5.el6_2 | Fixed | RHSA-2012:0514 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.31-1jpp.1.el6_2 | Fixed | RHSA-2012:0139 |
| Red Hat Enterprise Linux 4 | java-1.6.0-sun | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.11% (0.98113) | 99.91th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.20% (0.98198) | 99.91th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.10% (0.94103) | 99.90th | v4 (v2025.03.14) |
| Dec 17, 2024 | 93.84% (0.93844) | 99.35th | v3 (v2023.03.01) |
| Dec 12, 2024 | 96.62% (0.96621) | 99.69th | v3 (v2023.03.01) |
| Apr 27, 2024 | 96.76% (0.96756) | 99.66th | v3 (v2023.03.01) |
| Jan 6, 2024 | 97.32% (0.97320) | 99.86th | v3 (v2023.03.01) |
| Sep 1, 2023 | 97.34% (0.97336) | 99.82th | v3 (v2023.03.01) |
| Jul 2, 2023 | 97.39% (0.97394) | 99.86th | v3 (v2023.03.01) |
| Apr 28, 2023 | 97.34% (0.97340) | 99.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.31% (0.97312) | 99.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 76.28% (0.76282) | 99.38th | v2 (v2022.01.01) |
| Aug 22, 2022 | 76.28% (0.76282) | 99.33th | v2 (v2022.01.01) |
| May 21, 2022 | 76.91% (0.76907) | 99.34th | v2 (v2022.01.01) |
| Feb 16, 2022 | 77.89% (0.77893) | 99.32th | v2 (v2022.01.01) |
| Feb 4, 2022 | 79.14% (0.79135) | 99.37th | v2 (v2022.01.01) |
References (27)
- http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx x_refsource_MISCBroken LinkThird Party Advisory
- http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/ x_refsource_MISCThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html vendor-advisoryx_refsource_SUSEIssue TrackingThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=133364885411663&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://marc.info/?l=bugtraq&m=133365109612558&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://marc.info/?l=bugtraq&m=133847939902305&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://marc.info/?l=bugtraq&m=134254957702612&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0508.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0514.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1455.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/48589 third-party-advisoryx_refsource_SECUNIABroken LinkNot Applicable
- http://secunia.com/advisories/48692 third-party-advisoryx_refsource_SECUNIABroken LinkNot Applicable
- http://secunia.com/advisories/48915 third-party-advisoryx_refsource_SECUNIABroken LinkNot Applicable
- http://secunia.com/advisories/48948 third-party-advisoryx_refsource_SECUNIABroken LinkNot Applicable
- http://secunia.com/advisories/48950 third-party-advisoryx_refsource_SECUNIABroken LinkNot Applicable
- http://weblog.ikvm.net/PermaLink.aspx?guid=cd48169a-9405-4f63-9087-798c4a1866d3 x_refsource_MISCBroken LinkExploit
- http://www.debian.org/security/2012/dsa-2420 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/52161 vdb-entryx_refsource_BIDBroken LinkExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2012-0507 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=788994 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2012-0507
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0507 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2012-0507
Change history (0)
No recorded changes yet.