Vulnerability record · CVE-2010-0094 · published 1 April 2010
CVE-2010-0094: Oracle Java SE JRE Deserialization Privilege Check Flaw
Sun · Jre
CVE-2010-0094 is an unspecified vulnerability in the Java Runtime Environment component of Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23. Oracle has not confirmed researcher claims that it stems from missing privilege checks during deserialization of RMIConnectionImpl objects, which could let remote attackers invoke system-level Java functions via the ClassLoader of a constructor being deserialized. The flaw affects confidentiality, integrity, and availability.
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 score of 7.5 and EPSS 30-day probability above 0.80 indicate a high-likelihood, remotely reachable flaw affecting confidentiality, integrity, and availability.
What it is
CVE-2010-0094 is an unspecified vulnerability in the Java Runtime Environment component of Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23. Oracle has not confirmed researcher claims that it stems from missing privilege checks during deserialization of RMIConnectionImpl objects, which could let remote attackers invoke system-level Java functions via the ClassLoader of a constructor being deserialized. The flaw affects confidentiality, integrity, and availability.
Impact
A remote attacker could affect confidentiality, integrity, and availability of the affected Java runtime, potentially invoking system-level Java functions. The exact scope of control gained is not detailed in the record.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication required and low attack complexity. User interaction is not specified in the record.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS shows a 30-day probability of 0.80813 (99.6th percentile), indicating high predicted likelihood of exploitation activity. Reference tags are limited to Vendor Advisory, with no public exploit tags present.
What to do
- Apply the Oracle Java SE and Java for Business updates referenced in the March 2010 CPU and subsequent Oracle advisories.
- Apply vendor patches from Red Hat, Apple, Ubuntu, openSUSE, and Mandriva listed in the references for affected distributions.
- Upgrade to a supported Java runtime version that is no longer affected by this deserialization flaw.
- Restrict network exposure of Java RMI and deserialization endpoints to trusted hosts only.
- Monitor for and block untrusted Java serialized object streams where feasible.
Detection
- Monitor network traffic for Java RMI or deserialization activity from untrusted sources.
- Audit Java application logs for unexpected ClassLoader or RMIConnectionImpl deserialization errors.
- Track Java runtime versions in the environment against the affected 6 Update 18 and 5.0 Update 23 releases.
- Use host-based detection for unusual system-level Java function calls originating from deserialization paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0094 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0094), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.