Vulnerability record · CVE-2011-3556 · published 19 October 2011
CVE-2011-3556: Oracle Java RMI unspecified flaw allows remote compromise
Sun · Jdk
An unspecified vulnerability in the Java Runtime Environment's RMI component affects Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier. The record gives no root-cause detail beyond the RMI association, but the flaw lets remote attackers affect confidentiality, integrity and availability, making it a serious pre-auth exposure for any host running an unpatched JVM.
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, no authentication required, full confidentiality/integrity/availability impact, and a very high EPSS score, though no confirmed in-the-wild exploitation is recorded.
What it is
An unspecified vulnerability in the Java Runtime Environment's RMI component affects Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier. The record gives no root-cause detail beyond the RMI association, but the flaw lets remote attackers affect confidentiality, integrity and availability, making it a serious pre-auth exposure for any host running an unpatched JVM.
Impact
A remote attacker can impact confidentiality, integrity and availability of the affected Java process, potentially leading to code execution or data compromise within the JVM's privileges.
Attack surface
Reached over the network via RMI (AV:N/AC:L/Au:N), so no authentication or user interaction is required per the CVSS vector. Any service exposing RMI, or any client connecting to a malicious RMI endpoint, is in scope.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.76405 (99.5th percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Apply the Oracle October 2011 Critical Patch Update or later for Java SE and JRockit, and apply the referenced Red Hat, Ubuntu, openSUSE and Gentoo errata.
- Upgrade to a supported Java release; versions 1.4.2, 5.0 and 6 are long past end of life and should not remain in production.
- Restrict network access to RMI ports with host firewalls and segmentation; do not expose RMI listeners to untrusted networks.
- Disable or remove the RMI registry and RMI-based services where they are not required by the application.
- Inventory Java installations, including embedded JREs in third-party applications, so unpatched copies are not missed.
Detection
- Monitor for unexpected outbound or inbound connections to RMI registry ports (default 1099) from Java processes.
- Alert on Java processes spawning child processes or writing outside expected application directories, which can indicate post-exploitation.
- Track JVM versions across the estate and flag hosts still running 1.4.2, 5.0, 6 Update 27 or earlier, or JRockit R28.1.4 or earlier.
- Review application and JVM logs for RMI deserialization or class-loading anomalies around the time of suspicious network activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3556 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3556), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.