CVE-2011-3544 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
CVE-2011-3544: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Oracle |
| Product | Java SE JDK and JRE |
| Date added | 2022-03-03 |
| Due date | 2022-03-24 |
| Ransomware campaign use | Unknown |
Description
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2011-3544
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2011-3544
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog