CVE-2011-3544

Advisory lineage Upstream: 0 Downstream: 7
Analyzed
Published: 19 Oct 2011, 21:00
Last modified:22 Oct 2025, 00:05

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
92.55% CRITICAL
93% probability -0.41%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

19 Oct 2011, 21:00
Published
Vulnerability first disclosed
03 Mar 2022, 00:00
Added to CISA KEV
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
24 Mar 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
22 Oct 2025, 00:05
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 92.55% Percentile: 100%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • canonicalubuntu_linux

    10.04 | 10.10 | 11.04 | 11.10

  • oraclejdk

    < 1.6.0 | 1.6.0 | 1.6.0:update1 | 1.6.0:update10 | 1.6.0:update11 | 1.6.0:update12 | 1.6.0:update13 | 1.6.0:update14 | 1.6.0:update15 | 1.6.0:update16 | 1.6.0:update17 | 1.6.0:update18 | 1.6.0:update19 | 1.6.0:update2 | 1.6.0:update20 | 1.6.0:update21 | 1.6.0:update22 | 1.6.0:update23 | 1.6.0:update24 | 1.6.0:update25 | 1.6.0:update26 | 1.7.0 | 1.7.0:update1 | 1.7.0:update10 | 1.7.0:update11 | 1.7.0:update13 | 1.7.0:update15 | 1.7.0:update17 | 1.7.0:update2 | 1.7.0:update21 | 1.7.0:update25 | 1.7.0:update3 | 1.7.0:update4 | 1.7.0:update5 | 1.7.0:update6 | 1.7.0:update7 | 1.7.0:update7_b32 | 1.7.0:update9 | 1.7.0:update9_b31 | 1.7.0:update9_b32

  • oraclejre

    < 1.6.0 | 1.6.0 | 1.6.0:update1 | 1.6.0:update11 | 1.6.0:update12 | 1.6.0:update13 | 1.6.0:update14 | 1.6.0:update15 | 1.6.0:update16 | 1.6.0:update17 | 1.6.0:update18 | 1.6.0:update19 | 1.6.0:update2 | 1.6.0:update20 | 1.6.0:update21 | 1.6.0:update22 | 1.6.0:update23 | 1.6.0:update24 | 1.6.0:update25 | 1.6.0:update26 | 1.6.0:update3 | 1.6.0:update4 | 1.6.0:update5 | 1.6.0:update6 | 1.6.0:update7 | 1.6.0:update8 | 1.6.0:update9 | 1.7.0 | 1.7.0:update1 | 1.7.0:update10 | 1.7.0:update10_b31 | 1.7.0:update11 | 1.7.0:update13 | 1.7.0:update15 | 1.7.0:update17 | 1.7.0:update17_b31 | 1.7.0:update17_b32 | 1.7.0:update2 | 1.7.0:update21 | 1.7.0:update21_b31 | 1.7.0:update25 | 1.7.0:update25_b33 | 1.7.0:update25_b34 | 1.7.0:update25_b35 | 1.7.0:update3 | 1.7.0:update4 | 1.7.0:update5 | 1.7.0:update6 | 1.7.0:update7 | 1.7.0:update7_b32 | 1.7.0:update9

  • redhatsatellite_with_embedded_oracle

    5.4

  • suselinux_enterprise_java

    10:sp4

  • suselinux_enterprise_server

    10:sp4

References (16)