CVE-2011-3553
published 2011-10-19CVE-2011-3553: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier…
PriorityP418low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
2.21%
80.7th percentile
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jrockit | <= r28.1.4 | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_ubuntu4.3MEDIUM
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 regression
vendor_ubuntu·2012-01-24·CVSS 4.3
CVE-2011-3389 [MEDIUM] OpenJDK 6 regression
Title: OpenJDK 6 regression
Summary: USN-1263-1 caused a regression when using OpenJDK 6's SSL/TLS
implementation.
USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for
the chosen plaintext attack on the block-wise AES encryption algorithm
(CVE-2011-3389) introduced a regression that caused TLS/SSL connections
to fail when using certain algorithms. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as use
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-11-16·CVSS 4.3
CVE-2011-3389 [MEDIUM] IcedTea-Web, OpenJDK 6 vulnerabilities
Title: IcedTea-Web, OpenJDK 6 vulnerabilities
Summary: Multiple OpenJDK 6 and IcedTea-Web vulnerabilities have been fixed.
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as used in TLS/SSL was vulnerable to
a chosen-plaintext attack. This could allow a remote attacker to view
confidential data. (CVE-2011-3389)
It was discovered that a type confusion flaw existed in the in
the Internet Inter-Orb Protocol (IIOP) deserialization code. A
remote attacker could use this to cause an untrusted application
or applet to
Red Hat
OpenJDK: JAX-WS stack-traces information leak (JAX-WS, 7046794)
vendor_redhat·2011-10-18·CVSS 3.5
CVE-2011-3553 [LOW] OpenJDK: JAX-WS stack-traces information leak (JAX-WS, 7046794)
OpenJDK: JAX-WS stack-traces information leak (JAX-WS, 7046794)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 4) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 4) - Not affected
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.4.2-ibm-sap (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-pch5-2rr3-9w92: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28
ghsa_unreviewed·2022-05-14
CVE-2011-3553 [LOW] GHSA-pch5-2rr3-9w92: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlhttp://marc.info/?l=bugtraq&m=132750579901589&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://osvdb.org/76512http://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48308http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1384.htmlhttp://www.securityfocus.com/bid/50246http://www.securitytracker.com/id?1026215http://www.ubuntu.com/usn/USN-1263-1https://exchange.xforce.ibmcloud.com/vulnerabilities/70840https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14311http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlhttp://marc.info/?l=bugtraq&m=132750579901589&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://osvdb.org/76512http://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48308http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1384.htmlhttp://www.securityfocus.com/bid/50246http://www.securitytracker.com/id?1026215http://www.ubuntu.com/usn/USN-1263-1https://exchange.xforce.ibmcloud.com/vulnerabilities/70840https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14311
2011-10-19
Published