CVE-2011-3544

Confirmed PUBLISHED

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote...

Oracle · Java SE
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

java metasploit cisa
CVE Published
Oct 19, 2011
Exploitation Reported
Mar 03, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • GLSA-201406-32 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201406-32.xml
  • HPSBMU02799 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134254866602253&w=2
  • HPSBUX02730 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=132750579901589&w=2
  • SUSE-SU-2012:0114 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049...
  • RHSA-2013:1455 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-1455.html
Show 10 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.