Umbra Wiki cve cve/CVE-2011-3544
Back to wiki

CVE-2011-3544 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

provenance: imported · CVE: CVE-2011-3544

CVE-2011-3544: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Oracle
Product Java SE JDK and JRE
Date added 2022-03-03
Due date 2022-03-24
Ransomware campaign use Unknown

Description

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2011-3544

Weakness behind it

CISA has not recorded a CWE for this entry, so the CVE → CWE → CAPEC → ATT&CK chain cannot be walked from here. That is a gap in the catalogue, not evidence the vulnerability has no weakness class — check the NVD record below.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2011-3544
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →

Related pages