← Vulnerability feed

Vulnerability record · CVE-2011-3556 · published 19 October 2011

CVE-2011-3556: Oracle Java RMI unspecified flaw allows remote compromise

Sun · Jdk

An unspecified vulnerability in the Java Runtime Environment's RMI component affects Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier. The record gives no root-cause detail beyond the RMI association, but the flaw lets remote attackers affect confidentiality, integrity and availability, making it a serious pre-auth exposure for any host running an unpatched JVM.

7.5 CVSS 2.0 High EPSS 76% · top 0.5%
7.5CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
48References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable, no authentication required, full confidentiality/integrity/availability impact, and a very high EPSS score, though no confirmed in-the-wild exploitation is recorded.

What it is

An unspecified vulnerability in the Java Runtime Environment's RMI component affects Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier. The record gives no root-cause detail beyond the RMI association, but the flaw lets remote attackers affect confidentiality, integrity and availability, making it a serious pre-auth exposure for any host running an unpatched JVM.

Impact

A remote attacker can impact confidentiality, integrity and availability of the affected Java process, potentially leading to code execution or data compromise within the JVM's privileges.

Attack surface

Reached over the network via RMI (AV:N/AC:L/Au:N), so no authentication or user interaction is required per the CVSS vector. Any service exposing RMI, or any client connecting to a malicious RMI endpoint, is in scope.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.76405 (99.5th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Apply the Oracle October 2011 Critical Patch Update or later for Java SE and JRockit, and apply the referenced Red Hat, Ubuntu, openSUSE and Gentoo errata.
  • Upgrade to a supported Java release; versions 1.4.2, 5.0 and 6 are long past end of life and should not remain in production.
  • Restrict network access to RMI ports with host firewalls and segmentation; do not expose RMI listeners to untrusted networks.
  • Disable or remove the RMI registry and RMI-based services where they are not required by the application.
  • Inventory Java installations, including embedded JREs in third-party applications, so unpatched copies are not missed.

Detection

  • Monitor for unexpected outbound or inbound connections to RMI registry ports (default 1099) from Java processes.
  • Alert on Java processes spawning child processes or writing outside expected application directories, which can indicate post-exploitation.
  • Track JVM versions across the estate and flag hosts still running 1.4.2, 5.0, 6 Update 27 or earlier, or JRockit R28.1.4 or earlier.
  • Review application and JVM logs for RMI deserialization or class-loading anomalies around the time of suspicious network activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html
http://marc.info/?l=bugtraq&m=132750579901589&w=2
http://marc.info/?l=bugtraq&m=133365109612558&w=2
http://marc.info/?l=bugtraq&m=133728004526190&w=2
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://marc.info/?l=bugtraq&m=134254957702612&w=2
http://osvdb.org/76505
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://secunia.com/advisories/48308
http://secunia.com/advisories/48692
http://secunia.com/advisories/49198
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ibm.com/developerworks/java/jdk/alerts/
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2011-1384.html
http://www.redhat.com/support/errata/RHSA-2011-1478.html
http://www.redhat.com/support/errata/RHSA-2012-0006.html
http://www.securityfocus.com/bid/50231
http://www.securitytracker.com/id?1026215
http://www.ubuntu.com/usn/USN-1263-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/70837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14316
https://www.kb.cert.org/vuls/id/597809
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html
http://marc.info/?l=bugtraq&m=132750579901589&w=2
http://marc.info/?l=bugtraq&m=133365109612558&w=2
http://marc.info/?l=bugtraq&m=133728004526190&w=2
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://marc.info/?l=bugtraq&m=134254957702612&w=2
http://osvdb.org/76505
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://secunia.com/advisories/48308
http://secunia.com/advisories/48692
http://secunia.com/advisories/49198
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.ibm.com/developerworks/java/jdk/alerts/
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2011-1384.html

Track CVE-2011-3556 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed10.0CVE-2016-0483Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confi…EPSS 15%10.0CVE-2014-2421Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect con…EPSS 6.6%10.0CVE-2014-0456Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…EPSS 6.6%10.0CVE-2014-0457Oracle jrockit vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attack…EPSS 6.6%10.0CVE-2014-0429Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers…EPSS 7.3%

Source: NIST National Vulnerability Database (record CVE-2011-3556), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.