CVE-2011-3544
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.71% probability · 100th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-284
- Affected
- oracle/jdk · oracle/jre · canonical/ubuntu linux · redhat/satellite with embedded oracle · suse/linux enterprise java · suse/linux enterprise server
- Source
- secalert_us@oracle.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2011-3544
References
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132750579901589&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254866602253&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254957702612&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://secunia.com/advisories/48308Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.ibm.com/developerworks/java/jdk/alerts/Product
- http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1384.htmlBroken Link
- http://www.securityfocus.com/bid/50218Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026215Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1263-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70849Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132750579901589&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254866602253&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254957702612&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://secunia.com/advisories/48308Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.ibm.com/developerworks/java/jdk/alerts/Product
- http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1384.htmlBroken Link
- http://www.securityfocus.com/bid/50218Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026215Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1263-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70849Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.