CVE-2012-4820

critical
Published 2013-01-11 · Modified 2026-04-29
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://www-304.ibm.com/support/docview.wss?uid=swg21616546

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21631786

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21621154

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616708

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616652

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616617

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616616

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616594

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21616490

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21615800

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21615705

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV29654

Application impact

VendorProductVersionsFixed
ibm ibmjava{"startIncluding":"1.4.2","endIncluding":"1.4.2.13.13"}
ibm ibmlotus_domino8.0
ibm ibmlotus_domino8.0.1
ibm ibmlotus_domino8.0.2
ibm ibmlotus_domino8.0.2.1
ibm ibmlotus_domino8.0.2.2
ibm ibmlotus_domino8.0.2.3
ibm ibmlotus_domino8.0.2.4
ibm ibmlotus_domino8.5.0
ibm ibmlotus_domino8.5.0.1
ibm ibmlotus_domino8.5.1
ibm ibmlotus_domino8.5.1.1
ibm ibmlotus_domino8.5.1.2
ibm ibmlotus_domino8.5.1.3
ibm ibmlotus_domino8.5.1.4
ibm ibmlotus_domino8.5.1.5
ibm ibmlotus_domino8.5.2.0
ibm ibmlotus_domino8.5.2.1
ibm ibmlotus_domino8.5.2.2
ibm ibmlotus_domino8.5.2.3
ibm ibmlotus_domino8.5.2.4
ibm ibmlotus_domino8.5.3.0
ibm ibmlotus_domino8.5.3.1
ibm ibmlotus_domino8.5.3.2
ibm ibmlotus_notes8.0
ibm ibmlotus_notes8.0.0
ibm ibmlotus_notes8.0.1
ibm ibmlotus_notes8.0.2
ibm ibmlotus_notes8.0.2.0
ibm ibmlotus_notes8.0.2.1
ibm ibmlotus_notes8.0.2.2
ibm ibmlotus_notes8.0.2.3
ibm ibmlotus_notes8.0.2.4
ibm ibmlotus_notes8.0.2.5
ibm ibmlotus_notes8.0.2.6
ibm ibmlotus_notes8.5
ibm ibmlotus_notes8.5.0.0
ibm ibmlotus_notes8.5.0.1
ibm ibmlotus_notes8.5.1
ibm ibmlotus_notes8.5.1.0
ibm ibmlotus_notes8.5.1.1
ibm ibmlotus_notes8.5.1.2
ibm ibmlotus_notes8.5.1.3
ibm ibmlotus_notes8.5.1.4
ibm ibmlotus_notes8.5.1.5
ibm ibmlotus_notes8.5.2.0
ibm ibmlotus_notes8.5.2.1
ibm ibmlotus_notes8.5.2.2
ibm ibmlotus_notes8.5.2.3
ibm ibmlotus_notes8.5.3
ibm ibmlotus_notes8.5.3.1
ibm ibmlotus_notes8.5.3.2
ibm ibmlotus_notes8.5.4
ibm ibmlotus_notes_sametime8.0.80407
ibm ibmlotus_notes_sametime8.0.80822
ibm ibmlotus_notes_sametime8.5.1.20100709-1631
ibm ibmlotus_notes_traveler8.0
ibm ibmlotus_notes_traveler8.0.1
ibm ibmlotus_notes_traveler8.0.1.2
ibm ibmlotus_notes_traveler8.0.1.3
ibm ibmlotus_notes_traveler8.5.0.0
ibm ibmlotus_notes_traveler8.5.0.1
ibm ibmlotus_notes_traveler8.5.0.2
ibm ibmlotus_notes_traveler8.5.1.1
ibm ibmlotus_notes_traveler8.5.1.2
ibm ibmlotus_notes_traveler8.5.1.3
ibm ibmlotus_notes_traveler8.5.2.1
ibm ibmlotus_notes_traveler8.5.3
ibm ibmlotus_notes_traveler8.5.3.1
ibm ibmlotus_notes_traveler8.5.3.2
ibm ibmlotus_notes_traveler8.5.3.3
ibm ibmrational_change4.7
ibm ibmrational_change5.1
ibm ibmrational_change5.2
ibm ibmrational_change5.3
ibm ibmrational_host_on-demand1.6.0.12
ibm ibmrational_host_on-demand8.0.8.0
ibm ibmrational_host_on-demand9.0.8.0
ibm ibmrational_host_on-demand10.0.9.0
ibm ibmrational_host_on-demand10.0.10.0
ibm ibmrational_host_on-demand11.0.3.0
ibm ibmrational_host_on-demand11.0.4.0
ibm ibmrational_host_on-demand11.0.5.0
ibm ibmrational_host_on-demand11.0.5.1
ibm ibmrational_host_on-demand11.0.6.0
ibm ibmrational_host_on-demand11.0.6.1
ibm ibmservice_delivery_manager7.2.1.0
ibm ibmservice_delivery_manager7.2.2.0
ibm ibmsmart_analytics_system_5600_software-
ibm ibmsmart_analytics_system_5600_software9.7
ibm ibmtivoli_monitoring6.1.0
ibm ibmtivoli_monitoring6.1.0.7
ibm ibmtivoli_monitoring6.2.0
ibm ibmtivoli_monitoring6.2.0.1
ibm ibmtivoli_monitoring6.2.0.2
ibm ibmtivoli_monitoring6.2.0.3
ibm ibmtivoli_monitoring6.2.1
ibm ibmtivoli_monitoring6.2.1.0
ibm ibmtivoli_monitoring6.2.1.1
ibm ibmtivoli_monitoring6.2.1.2
ibm ibmtivoli_monitoring6.2.1.3
ibm ibmtivoli_monitoring6.2.1.4
ibm ibmtivoli_monitoring6.2.2
ibm ibmtivoli_monitoring6.2.2.0
ibm ibmtivoli_monitoring6.2.2.1
ibm ibmtivoli_monitoring6.2.2.2
ibm ibmtivoli_monitoring6.2.2.3
ibm ibmtivoli_monitoring6.2.2.4
ibm ibmtivoli_monitoring6.2.2.5
ibm ibmtivoli_monitoring6.2.2.6
ibm ibmtivoli_monitoring6.2.2.7
ibm ibmtivoli_monitoring6.2.2.8
ibm ibmtivoli_monitoring6.2.2.9
ibm ibmtivoli_monitoring6.2.3
ibm ibmtivoli_monitoring6.2.3.0
ibm ibmtivoli_monitoring6.2.3.1
ibm ibmtivoli_monitoring6.2.3.2
ibm ibmtivoli_remote_control5.1.2
ibm ibmwebsphere_real_time2.0
ibm ibmwebsphere_real_time3.0
tivoli_storage_productivity_center5.0
tivoli_storage_productivity_center5.1
tivoli_storage_productivity_center5.1.1

References

Verify integrity in audit chain (admin only). AS-IS.