PT-2011-1249 · Oracle+3 · Java Se Jdk+5
Publicado
2011-10-18
·
Atualizado
2025-03-13
·
CVE-2011-3544
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE JDK and JRE versions 6 Update 27 and earlier
Oracle Java SE JDK and JRE versions 7 and earlier
Description
The issue affects the Java Runtime Environment component, allowing remote untrusted Java Web Start applications and untrusted Java applets to impact confidentiality, integrity, and availability. This is related to insufficient protection of internal data in the Scripting component. The vulnerability can be exploited by a remote attacker to affect the integrity, availability, and confidentiality of protected information.
Recommendations
For Oracle Java SE JDK and JRE versions 6 Update 27 and earlier, update to a version later than Update 27 to resolve the issue.
For Oracle Java SE JDK and JRE versions 7 and earlier, update to a version later than 7 to resolve the issue.
As a temporary workaround, consider disabling the use of untrusted Java Web Start applications and untrusted Java applets until a patch is available.
Restrict access to the Scripting component to minimize the risk of exploitation.
Exploit
Correção
Information Disclosure
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp-Ux
Java Platform
Java Se Jdk
Java Se Jre
Red Hat
Suse