Back
CVE-2011-3544
CRITICAL
CISA KEV
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
Published: Oct 19, 2011
Modified: Apr 22, 2026
NVD-CWE-noinfo
CWE-284
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (98)
| Vendor | Product | Version |
|---|---|---|
| oracle | jdk | * < 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.6.0 |
…and 78 more
GitHub Security Advisory GHSA-25jq-3vh4-pgv4
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE...
References (31)
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=132750579901589&w=2 Mailing List
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 Mailing List
- http://marc.info/?l=bugtraq&m=134254957702612&w=2 Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
- http://secunia.com/advisories/48308 Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
- http://www.ibm.com/developerworks/java/jdk/alerts/ Product
- http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1384.html Broken Link
- http://www.securityfocus.com/bid/50218 Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026215 Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1263-1 Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70849 Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947 Broken Link
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
92.55%
Top 0% most likely to be exploited
Threat Score
97 / 100
CISA Known Exploited
Date Added:
2022-03-03
Due Date:
2022-03-24
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub