Vulnerability record · CVE-2010-3563 · published 19 October 2010
CVE-2010-3563: Oracle Java Web Start Deployment sandbox bypass via forged security policies
Sun · Jre
An unspecified vulnerability in the Deployment component of Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to compromise confidentiality, integrity, and availability. Oracle has not confirmed researcher claims that the flaw involves how Web Start retrieves security policies, BasicServiceImpl, and forged policies that bypass sandbox restrictions. Because the flaw is remotely reachable with no authentication and no known workaround beyond patching, it matters to any environment still running the affected Java releases.
Description
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to "how Web Start retrieves security policies," BasicServiceImpl, and forged policies that bypass sandbox restrictions.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0 with network reachability, no authentication, and full impact on confidentiality, integrity, and availability, plus a very high EPSS score, make this a top remediation priority despite the lack of confirmed in-the-wild exploitation in this record.
What it is
An unspecified vulnerability in the Deployment component of Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to compromise confidentiality, integrity, and availability. Oracle has not confirmed researcher claims that the flaw involves how Web Start retrieves security policies, BasicServiceImpl, and forged policies that bypass sandbox restrictions. Because the flaw is remotely reachable with no authentication and no known workaround beyond patching, it matters to any environment still running the affected Java releases.
Impact
An attacker can fully compromise confidentiality, integrity, and availability of the affected system, consistent with the CVSS 2.0 score of 10.0. In practice this means code execution or full sandbox escape on the Java client.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is network-reachable with low complexity and no authentication required. The description points to the Deployment component and Web Start, so the likely vector is a user launching a malicious Java Web Start application, though the exact trigger is not specified.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.8425, 99.68th percentile), but no reference is tagged as an exploit, so active exploitation is not confirmed by this record.
What to do
- Apply the Oracle October 2010 CPU patch referenced in the vendor advisory, or upgrade to a Java release that includes the fix.
- Apply the corresponding Red Hat, HP, Avaya, and openSUSE vendor updates where those platforms are in use.
- If patching is not immediately possible, restrict or disable Java Web Start and the Deployment component in browsers and on endpoints.
- Block untrusted JNLP/Web Start content at the network and email gateway, and enforce browser settings that require explicit user approval before launching Java content.
- Inventory endpoints and servers for Java SE/JDK 6 Update 21 and earlier so remediation can be prioritized.
Detection
- Monitor for JNLP file downloads and Java Web Start process launches, especially from external or untrusted origins.
- Alert on Java processes (javaws, java) spawning child processes or making unexpected outbound network connections.
- Review proxy and DNS logs for requests to known Java Web Start distribution points outside approved infrastructure.
- Check endpoint software inventory for Java SE/JDK 6 Update 21 or earlier and flag unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.