← Back to CVE List
Vulnerability Intelligence Report
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVE-2011-3544

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:96.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-284 ↗CWE-284 Improper Access Control

Affected Products & Versions

Vendor Product Affected Versions
oracle jdk 1.6.0, 1.7.0
oracle jre 1.6.0, 1.7.0
canonical ubuntu_linux 10.04, 10.10, 11.04, 11.10
redhat satellite_with_embedded_oracle 5.4
suse linux_enterprise_java 10
suse linux_enterprise_server 10

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
96.714%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOracle · Hosted Service · USA
Reserved2011-09-16T00:00:00
Published2011-10-19T21:00:00
Patch Date2011-10-18
Last Updated2025-10-22T00:05:49

LINK COPIED TO CLIPBOARD