EXPOSURES › CVE-2011-3544
CVE-2011-3544
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Java SE JRE had an access control flaw in the Rhino Script Engine allowing remote arbitrary code execution.
An access control vulnerability in the Applet Rhino Script Engine of Oracle's Java Runtime Environment allowed attackers to remotely execute arbitrary code. This is a critical failure for DIB organizations because Java is ubiquitous in enterprise environments, and unpatched RCE flaws are a primary vector for ransomware and data breaches. Organizations must ensure all Java components are patched to the latest version and monitored for KEV entries.
Shame score — This is a high embarrassment score because it is an actively exploited vulnerability (KEV) that enables remote code execution, representing a systemic failure in Oracle's security posture for a widely deployed product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |