Junglewise Threat Intelligence

CVE-2011-3544: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVE-2011-3544 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Oracle JRE, Oracle Java SE JDK. Vendors: Oracle.

Executive brief

An access control vulnerability in the Rhino Script Engine component of Oracle Java SE allows remote untrusted Java Web Start applications and applets to execute arbitrary code. The flaw impacts the confidentiality, integrity, and availability of the system via unknown vectors related to scripting.

Affected products

  • Oracle Java SE JDK 7, 6 Update 27 and earlier
  • Oracle Java SE JRE 7, 6 Update 27 and earlier

Timeline

  • 2011-10-18: patched: Oracle Critical Patch Update published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date

Related threats