🛡 CVE-2012-5076
Oracle Java SE Sandbox Bypass Vulnerability
Oracle Java SE
Ransomware use
—
CISA KEV
EPSS
91.0%
Likely exploited · 100th pct
Added to KEV
2022-03-28
CISA
Remediate by
2022-04-18
⚠ OVERDUE
CWE
—
weakness
📈 EPSS exploit probability
91.0%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-04-18. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron