Remote Code Execution Vulnerability in IBM Java Products
CVE-2012-4823
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 11 January 2013
What is CVE-2012-4823?
An unspecified vulnerability exists in the JRE component of IBM Java, affecting various versions up to and including Java 7 SR2. This flaw enables remote attackers to execute arbitrary code on targeted systems by exploiting insecure usage of the java.lang.ClassLoader defineClass() method. The vulnerability impacts a range of IBM products, including Rational Host On-Demand and Tivoli Monitoring, as well as other software from third-party vendors like Red Hat.