Vulnerability record · CVE-2010-0886 · published 20 April 2010
CVE-2010-0886: Oracle Java Deployment Toolkit remote code execution flaw
Sun · Jre
An unspecified vulnerability in the Java Deployment Toolkit component of Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to compromise confidentiality, integrity, and availability through unknown vectors. The record gives no technical detail on the root cause, so defenders must rely on the vendor patch and version range rather than a specific mechanism.
Description
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and very high EPSS percentile make this a top remediation priority despite the lack of technical detail.
What it is
An unspecified vulnerability in the Java Deployment Toolkit component of Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to compromise confidentiality, integrity, and availability through unknown vectors. The record gives no technical detail on the root cause, so defenders must rely on the vendor patch and version range rather than a specific mechanism.
Impact
A successful attack can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means an attacker could execute code or otherwise take control of the Java runtime and the host.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that cannot be confirmed from this record.
Exploitation
CVE-2010-0886 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.69949 (99.34th percentile), indicating high modeled likelihood of exploitation activity. No reference is tagged as exploit code, so public exploit availability is not confirmed by this record.
What to do
- Apply the Oracle patch referenced in the vendor advisory alert for CVE-2010-0886.
- Upgrade or remove Java 6 Update 10 through 19; do not run the affected JDK/JRE versions.
- Disable or restrict the Java Deployment Toolkit and browser Java plug-in where not required.
- Apply the Apple and VMware updates referenced in the advisories for affected platforms.
- Restrict outbound and inbound Java-related network exposure on hosts that must retain Java.
Detection
- Inventory hosts and applications still running Java 6 Update 10 through 19.
- Monitor for Java Deployment Toolkit process or plug-in activity spawning unexpected child processes.
- Alert on network connections from Java processes to untrusted external hosts.
- Review endpoint logs for unusual file writes or execution originating from the Java runtime.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0886 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0886), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.