<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - October 2012 - BETA ORACLE CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>JavaCPUOct2012</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2012-10-16T13:01:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2012-10-16T13:01:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2012-10-16T13:01:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Type="Summary" Ordinal="1" Title="Summary" Audience="All" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1841211.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Adam Gowdiak</Name>
         <Organization>Security Explorations</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Chris Ries</Name>
         <Organization>iDefense</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Christopher Meyer</Name>
         <Organization>Ruhr-University Bochum</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Eugen Weiss</Name>
         <Organization>Ruhr-University Bochum</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Juraj Somorovsky</Name>
         <Organization>Ruhr-University Bochum</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rh0</Name>
         <Organization>iDefense</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>an Anonymous Reporter via iDefense</Name>
         <Organization>iDefense</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Type="Vendor" Name="Oracle">
         <Branch Type="Product Family" Name="Oracle Java SE">
            <Branch Type="Product Name" Name="Sun Java">
               <Branch Type="Product Version" Name="1.4.2_38 and before">
                  <FullProductName ProductID="P-856V-1.4.2_38 and before">Sun Java Version 1.4.2_38 and before</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.0 Update 36 and before">
                  <FullProductName ProductID="P-856V-5.0 Update 36 and before">Sun Java Version 5.0 Update 36 and before</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6 Update 35 and before">
                  <FullProductName ProductID="P-856V-6 Update 35 and before">Sun Java Version 6 Update 35 and before</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7 Update 7 and before">
                  <FullProductName ProductID="P-856V-7 Update 7 and before">Sun Java Version 7 Update 7 and before</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="JavaFX 2.2 and before">
                  <FullProductName ProductID="P-856V-JavaFX 2.2 and before">Sun Java Version JavaFX 2.2 and before</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1531</Title>
      <Notes>
         <Note Type="Details" Ordinal="1" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before, 1.4.2_38 and before and  JavaFX 2.2 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through untrusted Java Web Start applications and untrusted Java applets. It can also be exploited by supplying data to APIs in the specified Component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1532</Title>
      <Notes>
         <Note Type="Details" Ordinal="2" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1532</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1533</Title>
      <Notes>
         <Note Type="Details" Ordinal="3" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1533</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3143</Title>
      <Notes>
         <Note Type="Details" Ordinal="4" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3143</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3143</Title>
      <Notes>
         <Note Type="Details" Ordinal="5" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3143</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3159</Title>
      <Notes>
         <Note Type="Details" Ordinal="6" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data and ability to cause a partial denial of service (partial DOS) of Java Runtime Environment.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3159</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3216</Title>
      <Notes>
         <Note Type="Details" Ordinal="7" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3216</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-4416</Title>
      <Notes>
         <Note Type="Details" Ordinal="8" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-4416</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5067</Title>
      <Notes>
         <Note Type="Details" Ordinal="9" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5067</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5068</Title>
      <Notes>
         <Note Type="Details" Ordinal="10" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data and ability to cause a partial denial of service (partial DOS) of Java Runtime Environment.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5068</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5069</Title>
      <Notes>
         <Note Type="Details" Ordinal="11" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Concurrency).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5069</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5070</Title>
      <Notes>
         <Note Type="Details" Ordinal="12" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5070</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5071</Title>
      <Notes>
         <Note Type="Details" Ordinal="13" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5071</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5072</Title>
      <Notes>
         <Note Type="Details" Ordinal="14" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5072</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5073</Title>
      <Notes>
         <Note Type="Details" Ordinal="15" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5073</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5074</Title>
      <Notes>
         <Note Type="Details" Ordinal="16" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JAX-WS).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data as well as  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5074</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5075</Title>
      <Notes>
         <Note Type="Details" Ordinal="17" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5075</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5076</Title>
      <Notes>
         <Note Type="Details" Ordinal="18" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JAX-WS).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5076</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5077</Title>
      <Notes>
         <Note Type="Details" Ordinal="19" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5077</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5078</Title>
      <Notes>
         <Note Type="Details" Ordinal="20" Title="Details" Audience="All">Vulnerability in the JavaFX component of Oracle Java SE.  Supported versions that are affected are JavaFX 2.2 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5078</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5079</Title>
      <Notes>
         <Note Type="Details" Ordinal="21" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5079</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5080</Title>
      <Notes>
         <Note Type="Details" Ordinal="22" Title="Details" Audience="All">Vulnerability in the JavaFX component of Oracle Java SE.  Supported versions that are affected are JavaFX 2.2 and before. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5080</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5081</Title>
      <Notes>
         <Note Type="Details" Ordinal="23" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JSSE).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java Runtime Environment.   Note: Applies to server deployments of JSSE. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5081</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5082</Title>
      <Notes>
         <Note Type="Details" Ordinal="24" Title="Details" Audience="All">Vulnerability in the JavaFX component of Oracle Java SE.  Supported versions that are affected are JavaFX 2.2 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JavaFX.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5082</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5083</Title>
      <Notes>
         <Note Type="Details" Ordinal="25" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before, 1.4.2_38 and before and  JavaFX 2.2 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through untrusted Java Web Start applications and untrusted Java applets. It can also be exploited by supplying data to APIs in the specified Component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5083</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5083</Title>
      <Notes>
         <Note Type="Details" Ordinal="26" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before, 1.4.2_38 and before and  JavaFX 2.2 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through untrusted Java Web Start applications and untrusted Java applets. It can also be exploited by supplying data to APIs in the specified Component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5083</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
            <ProductID>P-856V-JavaFX 2.2 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5084</Title>
      <Notes>
         <Note Type="Details" Ordinal="27" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Swing).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5084</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5085</Title>
      <Notes>
         <Note Type="Details" Ordinal="28" Title="Details" Audience="All">Security-in-Depth issue in the Java Runtime Environment component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before, 5.0 Update 36 and before and  1.4.2_38 and before. CVSS Base Score 0.0. CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5085</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>0.0</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
            <ProductID>P-856V-1.4.2_38 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5086</Title>
      <Notes>
         <Note Type="Details" Ordinal="29" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Beans).  Supported versions that are affected are 7 Update 7 and before and  6 Update 35 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5087</Title>
      <Notes>
         <Note Type="Details" Ordinal="30" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Beans).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5087</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5088</Title>
      <Notes>
         <Note Type="Details" Ordinal="31" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 7 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5088</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5089</Title>
      <Notes>
         <Note Type="Details" Ordinal="32" Title="Details" Audience="All">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 7 and before, 6 Update 35 and before and  5.0 Update 36 and before. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications
and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5089</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html</URL>
            <ProductID>P-856V-7 Update 7 and before</ProductID>
            <ProductID>P-856V-6 Update 35 and before</ProductID>
            <ProductID>P-856V-5.0 Update 36 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
