Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability

BID:48134

Info

Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability

Bugtraq ID: 48134
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2011-0817
Remote: Yes
Local: No
Published: Jun 07 2011 12:00AM
Updated: Mar 19 2015 08:13AM
Credit: Stephen Fewer of Harmony Security
Vulnerable: SuSE SUSE Linux Enterprise Teradata 10 SP3
SuSE SUSE Linux Enterprise Server 11 SP1
SuSE SUSE Linux Enterprise Server 10 SP4
SuSE SUSE Linux Enterprise Server 10 SP3
SuSE SUSE Linux Enterprise SDK 11 SP1
SuSE SUSE Linux Enterprise Java 11 SP1
SuSE SUSE Linux Enterprise Java 10 SP4
SuSE SUSE Linux Enterprise Java 10 SP3
+ Linux kernel 2.6.5
SuSE SUSE Linux Enterprise Desktop 11 SP1
+ Linux kernel 2.6.5
SuSE SUSE Linux Enterprise Desktop 10 SP4
+ Linux kernel 2.6.5
SuSE openSUSE 11.4
SuSE openSUSE 11.3
Sun JRE (Windows Production Release) 1.6 _17
Sun JRE (Windows Production Release) 1.6 _13
Sun JRE (Windows Production Release) 1.6 _12
Sun JRE (Windows Production Release) 1.6 _10
Sun JRE (Windows Production Release) 1.6 _07
Sun JRE (Windows Production Release) 1.6 _06
Sun JRE (Windows Production Release) 1.6 _05
Sun JRE (Windows Production Release) 1.6 _04
Sun JRE (Windows Production Release) 1.6
Sun JRE (Windows Production Release) 1.6.0_25
Sun JRE (Windows Production Release) 1.6.0_24
Sun JRE (Windows Production Release) 1.6.0_23
Sun JRE (Windows Production Release) 1.6.0_22
Sun JRE (Windows Production Release) 1.6.0_21
Sun JRE (Windows Production Release) 1.6.0_20
Sun JRE (Windows Production Release) 1.6.0_2
Sun JRE (Windows Production Release) 1.6.0_19
Sun JRE (Windows Production Release) 1.6.0_18
Sun JRE (Windows Production Release) 1.6.0_15
Sun JRE (Windows Production Release) 1.6.0_14
Sun JRE (Windows Production Release) 1.6.0_11
Sun JRE (Windows Production Release) 1.6.0_03
Sun JRE (Windows Production Release) 1.6.0_02
Sun JRE (Windows Production Release) 1.6.0_01
Sun JDK (Windows Production Release) 1.6 _17
Sun JDK (Windows Production Release) 1.6 _14
Sun JDK (Windows Production Release) 1.6 _13
Sun JDK (Windows Production Release) 1.6 _11
Sun JDK (Windows Production Release) 1.6 _10
Sun JDK (Windows Production Release) 1.6 _07
Sun JDK (Windows Production Release) 1.6 _06
Sun JDK (Windows Production Release) 1.6 _05
Sun JDK (Windows Production Release) 1.6 _04
Sun JDK (Windows Production Release) 1.6
Sun JDK (Windows Production Release) 1.6.0_25
Sun JDK (Windows Production Release) 1.6.0_24
Sun JDK (Windows Production Release) 1.6.0_23
Sun JDK (Windows Production Release) 1.6.0_22
Sun JDK (Windows Production Release) 1.6.0_21
Sun JDK (Windows Production Release) 1.6.0_20
Sun JDK (Windows Production Release) 1.6.0_19
Sun JDK (Windows Production Release) 1.6.0_18
Sun JDK (Windows Production Release) 1.6.0_15
Sun JDK (Windows Production Release) 1.6.0_03
Sun JDK (Windows Production Release) 1.6.0_02
Sun JDK (Windows Production Release) 1.6.0_01-b06
Sun JDK (Windows Production Release) 1.6.0_01
Pardus Linux 2009 0
IBM Java SE 6.0.0 SR9
IBM Java SE 6.0 SR7
IBM Java SE 6.0 SR6
IBM Java SE 6.0 SR5
IBM Java SE 6.0
IBM Java SE 6 SR8 FP1
HP Systems Insight Manager 6.3
HP Systems Insight Manager 6.2
HP Systems Insight Manager 6.1
HP Systems Insight Manager 6.0.0.96
HP Systems Insight Manager 6.0
HP Systems Insight Manager 5.3 Update 1
HP Systems Insight Manager 5.3
HP Systems Insight Manager 5.2 SP2
HP Systems Insight Manager 5.1 SP1
HP Systems Insight Manager 5.0 SP6
HP Systems Insight Manager 5.0 SP5
HP Systems Insight Manager 5.0 SP3
HP Systems Insight Manager 5.0 SP2
HP Systems Insight Manager 5.0 SP1
HP Systems Insight Manager 5.0
HP Systems Insight Manager 4.2 SP2
HP Systems Insight Manager 4.2 SP1
HP Systems Insight Manager 4.2
HP NonStop Server J06.13
HP NonStop Server J06.12.00
HP NonStop Server J06.11.01
HP NonStop Server J06.11.00
HP NonStop Server J06.10.02
HP NonStop Server J06.10.01
HP NonStop Server J06.10.00
HP NonStop Server J06.09.04
HP NonStop Server J06.09.03
HP NonStop Server J06.09.02
HP NonStop Server J06.09.01
HP NonStop Server J06.09.00
HP NonStop Server J06.08.04
HP NonStop Server J06.08.03
HP NonStop Server J06.08.02
HP NonStop Server J06.08.01
HP NonStop Server J06.08.00
HP NonStop Server J06.07.02
HP NonStop Server J06.07.01
HP NonStop Server J06.07.00
HP NonStop Server J06.06.03
HP NonStop Server J06.06.02
HP NonStop Server J06.06.01
HP NonStop Server J06.06.00
HP NonStop Server J06.05.02
HP NonStop Server J06.05.01
HP NonStop Server J06.05.00
HP NonStop Server J06.04.02
HP NonStop Server J06.04.01
HP NonStop Server J06.04.00
HP NonStop Server H06.24
HP NonStop Server H06.23
HP NonStop Server H06.22.01
HP NonStop Server H06.22.00
HP NonStop Server H06.21.02
HP NonStop Server H06.21.01
HP NonStop Server H06.21.00
HP NonStop Server H06.20.03
HP NonStop Server H06.20.02
HP NonStop Server H06.20.01
HP NonStop Server H06.20.00
HP NonStop Server H06.19.03
HP NonStop Server H06.19.02
HP NonStop Server H06.19.01
HP NonStop Server H06.19.00
HP NonStop Server H06.18.02
HP NonStop Server H06.18.01
HP NonStop Server H06.18.00
HP NonStop Server H06.17.03
HP NonStop Server H06.17.02
HP NonStop Server H06.17.01
HP NonStop Server H06.17.00
HP NonStop Server H06.16.02
HP NonStop Server H06.16.01
HP NonStop Server H06.16.00
HP NonStop Server H06.15.02
HP NonStop Server H06.15.01
HP NonStop Server H06.15.00
HP HP-UX B.11.31
HP HP-UX B.11.23
HP HP-UX B.11.11
Not Vulnerable: Sun JRE (Windows Production Release) 1.6.0_26
Sun JDK (Windows Production Release) 1.6.0_26
IBM Java SE 6.0.0 SR9-FP2
HP Systems Insight Manager 7.0

Discussion

Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability

Oracle Java SE and Java for Business are prone to a remote code-execution vulnerability in the Java Runtime Environment. The issue occurs because of a NULL pointer dereference error.

The vulnerability can be exploited over multiple protocols.

Attackers can exploit this issue by enticing an unsuspecting user to visit a specially crafted webpage. A successful exploit will result in arbitrary code being executed in the context of the user running the browser. Failed exploit attempts will likely result in denial-of-service conditions.

This vulnerability affects the following supported versions:

6 Update 25

Exploit / POC

Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability

Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability

Solution:
Updates are available. Please see the references for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report