Executive brief
An access control vulnerability in the Rhino Script Engine component of Oracle Java SE allows remote untrusted Java Web Start applications and applets to execute arbitrary code. The flaw impacts the confidentiality, integrity, and availability of the system via unknown vectors related to scripting.
Affected products
- Oracle Java SE JDK 7, 6 Update 27 and earlier
- Oracle Java SE JRE 7, 6 Update 27 and earlier
Timeline
- 2011-10-18: patched: Oracle Critical Patch Update published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date