← Vulnerability feed

Vulnerability record · CVE-2010-0094 · published 1 April 2010

CVE-2010-0094: Oracle Java SE JRE Deserialization Privilege Check Flaw

Sun · Jre

CVE-2010-0094 is an unspecified vulnerability in the Java Runtime Environment component of Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23. Oracle has not confirmed researcher claims that it stems from missing privilege checks during deserialization of RMIConnectionImpl objects, which could let remote attackers invoke system-level Java functions via the ClassLoader of a constructor being deserialized. The flaw affects confidentiality, integrity, and availability.

7.5 CVSS 2.0 High EPSS 81% · top 0.4%
7.5CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
70References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 2.0 score of 7.5 and EPSS 30-day probability above 0.80 indicate a high-likelihood, remotely reachable flaw affecting confidentiality, integrity, and availability.

What it is

CVE-2010-0094 is an unspecified vulnerability in the Java Runtime Environment component of Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23. Oracle has not confirmed researcher claims that it stems from missing privilege checks during deserialization of RMIConnectionImpl objects, which could let remote attackers invoke system-level Java functions via the ClassLoader of a constructor being deserialized. The flaw affects confidentiality, integrity, and availability.

Impact

A remote attacker could affect confidentiality, integrity, and availability of the affected Java runtime, potentially invoking system-level Java functions. The exact scope of control gained is not detailed in the record.

Attack surface

The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication required and low attack complexity. User interaction is not specified in the record.

Exploitation

The CVE is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS shows a 30-day probability of 0.80813 (99.6th percentile), indicating high predicted likelihood of exploitation activity. Reference tags are limited to Vendor Advisory, with no public exploit tags present.

What to do

  • Apply the Oracle Java SE and Java for Business updates referenced in the March 2010 CPU and subsequent Oracle advisories.
  • Apply vendor patches from Red Hat, Apple, Ubuntu, openSUSE, and Mandriva listed in the references for affected distributions.
  • Upgrade to a supported Java runtime version that is no longer affected by this deserialization flaw.
  • Restrict network exposure of Java RMI and deserialization endpoints to trusted hosts only.
  • Monitor for and block untrusted Java serialized object streams where feasible.

Detection

  • Monitor network traffic for Java RMI or deserialization activity from untrusted sources.
  • Audit Java application logs for unexpected ClassLoader or RMIConnectionImpl deserialization errors.
  • Track Java runtime versions in the environment against the affected 6 Update 18 and 5.0 Update 23 releases.
  • Use host-based detection for unusual system-level Java function calls originating from deserialization paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
http://marc.info/?l=bugtraq&m=127557596201693&w=2
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/39292 Vendor Advisory
http://secunia.com/advisories/39317 Vendor Advisory
http://secunia.com/advisories/39659 Vendor Advisory
http://secunia.com/advisories/39819 Vendor Advisory
http://secunia.com/advisories/40545 Vendor Advisory
http://secunia.com/advisories/43308 Vendor Advisory
http://support.apple.com/kb/HT4170
http://support.apple.com/kb/HT4171
http://ubuntu.com/usn/usn-923-1
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html
http://www.redhat.com/support/errata/RHSA-2010-0337.html
http://www.redhat.com/support/errata/RHSA-2010-0338.html
http://www.redhat.com/support/errata/RHSA-2010-0339.html
http://www.redhat.com/support/errata/RHSA-2010-0383.html
http://www.redhat.com/support/errata/RHSA-2010-0471.html
http://www.securityfocus.com/archive/1/510527/100/0/threaded
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
http://www.vupen.com/english/advisories/2010/1107 Vendor Advisory
http://www.vupen.com/english/advisories/2010/1191 Vendor Advisory
http://www.vupen.com/english/advisories/2010/1454 Vendor Advisory
http://www.vupen.com/english/advisories/2010/1793 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-10-051
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10851
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14351
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html

Track CVE-2010-0094 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed10.0CVE-2013-5809Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 5.9%10.0CVE-2013-5814Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5817Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5824Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5782Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…EPSS 6.3%10.0CVE-2013-5787Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2010-0094), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.