SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2011-3544

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 96.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
96.71% probability · 100th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Weakness
CWE-284
Affected
oracle/jdk · oracle/jre · canonical/ubuntu linux · redhat/satellite with embedded oracle · suse/linux enterprise java · suse/linux enterprise server
Source
secalert_us@oracle.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2011-3544

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.