EXPOSURES › CVE-2010-0840
CVE-2010-0840
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unspecified vulnerability in Oracle's Java Runtime Environment (JRE) was actively exploited in the wild, affecting confidentiality, integrity, and availability.
Oracle's JRE contains an unspecified vulnerability that allows remote attackers to compromise confidentiality, integrity, and availability. This failure matters to DIB organizations because the Java runtime is ubiquitous in enterprise environments, and unpatched JREs are a primary vector for ransomware and data breaches. Organizations must rigorously patch JREs and monitor for KEV-listed exploits to prevent lateral movement and compliance violations.
Shame score — The vulnerability was actively exploited in the wild (KEV-listed), indicating a failure to patch a known or exploitable flaw before adversaries weaponized it, which is a severe negligence failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |