CVE-2011-3544
oracle jdk, oracle jre, canonical ubuntu linux
Published 19 Oct 2011 · updated 16 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
References
- lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html · Mailing List, Third Party Advisory
- marc.info/?l=bugtraq&m=132750579901589&w=2 · Mailing List
- marc.info/?l=bugtraq&m=134254866602253&w=2 · Mailing List
- marc.info/?l=bugtraq&m=134254957702612&w=2 · Mailing List
- rhn.redhat.com/errata/RHSA-2013-1455.html · Third Party Advisory
- secunia.com/advisories/48308 · Broken Link
- security.gentoo.org/glsa/glsa-201406-32.xml · Third Party Advisory
- www.ibm.com/developerworks/java/jdk/alerts/ · Product
- www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html · Patch, Vendor Advisory
- www.redhat.com/support/errata/RHSA-2011-1384.html · Broken Link
- www.securityfocus.com/bid/50218 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id?1026215 · Broken Link, Third Party Advisory, VDB Entry
- www.ubuntu.com/usn/USN-1263-1 · Third Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/70849 · Third Party Advisory, VDB Entry
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13947 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-3544 · US Government Resource