CVE-2012-0547: Oracle JDK

Low severity, CVSS 0.0. EPSS: 12.5% chance of exploitation in the next 30 days.

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

Affected products

  • Oracle JDK: version 1.7.0 only; up to and including 1.6.0; version 1.6.0 only
  • Oracle JRE: up to and including 1.7.0; version 1.7.0 only; up to and including 1.6.0; version 1.6.0 only
  • Sun JDK: version 1.6.0 only
  • Sun JRE: version 1.6.0 only

Published 2012-08-30. Last modified 2026-06-16.