← Vulnerability feed

Vulnerability record · CVE-2010-3563 · published 19 October 2010

CVE-2010-3563: Oracle Java Web Start Deployment sandbox bypass via forged security policies

Sun · Jre

An unspecified vulnerability in the Deployment component of Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to compromise confidentiality, integrity, and availability. Oracle has not confirmed researcher claims that the flaw involves how Web Start retrieves security policies, BasicServiceImpl, and forged policies that bypass sandbox restrictions. Because the flaw is remotely reachable with no authentication and no known workaround beyond patching, it matters to any environment still running the affected Java releases.

10.0 CVSS 2.0 High EPSS 84% · top 0.3%
10.0CVSS 2.0 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to "how Web Start retrieves security policies," BasicServiceImpl, and forged policies that bypass sandbox restrictions.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and full impact on confidentiality, integrity, and availability, plus a very high EPSS score, make this a top remediation priority despite the lack of confirmed in-the-wild exploitation in this record.

What it is

An unspecified vulnerability in the Deployment component of Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to compromise confidentiality, integrity, and availability. Oracle has not confirmed researcher claims that the flaw involves how Web Start retrieves security policies, BasicServiceImpl, and forged policies that bypass sandbox restrictions. Because the flaw is remotely reachable with no authentication and no known workaround beyond patching, it matters to any environment still running the affected Java releases.

Impact

An attacker can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means code execution or full sandbox escape on the Java client.

Attack surface

The CVSS vector AV:N/AC:L/Au:N indicates the flaw is network-reachable with low complexity and no authentication required. The description points to the Deployment component and Web Start, so the likely vector is a user launching a malicious Java Web Start application, though the exact trigger is not specified.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.8425, 99.68th percentile), but no reference is tagged as an exploit, so active exploitation is not confirmed by this record.

What to do

  • Apply the Oracle October 2010 CPU patch referenced in the vendor advisory, or upgrade to a Java release that includes the fix.
  • Apply the corresponding Red Hat, HP, Avaya, and openSUSE vendor updates where those platforms are in use.
  • If patching is not immediately possible, restrict or disable Java Web Start and the Deployment component in browsers and on endpoints.
  • Block untrusted JNLP/Web Start content at the network and email gateway, and enforce browser settings that require explicit user approval before launching Java content.
  • Inventory endpoints and servers for Java SE/JDK 6 Update 21 and earlier so remediation can be prioritized.

Detection

  • Monitor for JNLP file downloads and Java Web Start process launches, especially from external or untrusted origins.
  • Alert on Java processes (javaws, java) spawning child processes or making unexpected outbound network connections.
  • Review proxy and DNS logs for requests to known Java Web Start distribution points outside approved infrastructure.
  • Check endpoint software inventory for Java SE/JDK 6 Update 21 or earlier and flag unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/44954 Vendor Advisory
http://support.avaya.com/css/P8/documents/100114315
http://support.avaya.com/css/P8/documents/100123193
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0770.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0987.html
http://www.redhat.com/support/errata/RHSA-2011-0880.html Vendor Advisory
http://www.securityfocus.com/bid/43999
http://www.zerodayinitiative.com/advisories/ZDI-10-202/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12181
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12554
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/44954 Vendor Advisory
http://support.avaya.com/css/P8/documents/100114315
http://support.avaya.com/css/P8/documents/100123193
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0770.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0987.html
http://www.redhat.com/support/errata/RHSA-2011-0880.html Vendor Advisory
http://www.securityfocus.com/bid/43999
http://www.zerodayinitiative.com/advisories/ZDI-10-202/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12181
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12554

Track CVE-2010-3563 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed10.0CVE-2013-5809Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 5.9%10.0CVE-2013-5814Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5817Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5824Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5782Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…EPSS 6.3%10.0CVE-2013-5787Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2010-3563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.