← Vulnerability feed

Vulnerability record · CVE-2010-0886 · published 20 April 2010

CVE-2010-0886: Oracle Java Deployment Toolkit remote code execution flaw

Sun · Jre

An unspecified vulnerability in the Java Deployment Toolkit component of Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to compromise confidentiality, integrity, and availability through unknown vectors. The record gives no technical detail on the root cause, so defenders must rely on the vendor patch and version range rather than a specific mechanism.

10.0 CVSS 2.0 High EPSS 70% · top 0.6%
10.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and very high EPSS percentile make this a top remediation priority despite the lack of technical detail.

What it is

An unspecified vulnerability in the Java Deployment Toolkit component of Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to compromise confidentiality, integrity, and availability through unknown vectors. The record gives no technical detail on the root cause, so defenders must rely on the vendor patch and version range rather than a specific mechanism.

Impact

A successful attack can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means an attacker could execute code or otherwise take control of the Java runtime and the host.

Attack surface

The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that cannot be confirmed from this record.

Exploitation

CVE-2010-0886 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.69949 (99.34th percentile), indicating high modeled likelihood of exploitation activity. No reference is tagged as exploit code, so public exploit availability is not confirmed by this record.

What to do

  • Apply the Oracle patch referenced in the vendor advisory alert for CVE-2010-0886.
  • Upgrade or remove Java 6 Update 10 through 19; do not run the affected JDK/JRE versions.
  • Disable or restrict the Java Deployment Toolkit and browser Java plug-in where not required.
  • Apply the Apple and VMware updates referenced in the advisories for affected platforms.
  • Restrict outbound and inbound Java-related network exposure on hosts that must retain Java.

Detection

  • Inventory hosts and applications still running Java 6 Update 10 through 19.
  • Monitor for Java Deployment Toolkit process or plug-in activity spawning unexpected child processes.
  • Alert on network connections from Java processes to untrusted external hosts.
  • Review endpoint logs for unusual file writes or execution originating from the Java runtime.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/39819
http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1
http://support.apple.com/kb/HT4170
http://support.apple.com/kb/HT4171
http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
http://www.vupen.com/english/advisories/2010/1191
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14216
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/39819
http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1
http://support.apple.com/kb/HT4170
http://support.apple.com/kb/HT4171
http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
http://www.vupen.com/english/advisories/2010/1191
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14216

Track CVE-2010-0886 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed10.0CVE-2013-5809Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 5.9%10.0CVE-2013-5814Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5817Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5824Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5782Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…EPSS 6.3%10.0CVE-2013-5787Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2010-0886), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.