CVE-2012-1723: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 93.7% chance of exploitation in the next 30 days.

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Affected products

  • Oracle JDK: up to and including 1.4.2_37; version 1.5.0 only; version 1.6.0 only; version 1.7.0 only
  • Oracle JRE: up to and including 1.4.2_37; version 1.5.0 only; version 1.6.0 only; version 1.7.0 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.2 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.2 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Red Hat ICEDTEA6: before 1.10.8 (fixed in 1.10.8); from 1.11.0, before 1.11.3 (fixed in 1.11.3)

Published 2012-06-16. Last modified 2026-08-06.