CVE-2011-3556
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 76%
from disclosure to weapon0 days
Published on NVDOct 19
1st PoCJul 15
metasploitOct 15
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.
Affected products
n/a · n/apublic PoCs found — 2
githubgithub.com/sk4la/cve_2011_3556★ 1exploitdbwww.exploit-db.com/exploits/17535unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.htmlhttp://marc.info/?l=bugtraq&m=132750579901589&w=2http://marc.info/?l=bugtraq&m=133365109612558&w=2http://marc.info/?l=bugtraq&m=133728004526190&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://osvdb.org/76505http://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48308http://secunia.com/advisories/48692http://secunia.com/advisories/49198