Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
BID:50237
Info
Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
| Bugtraq ID: | 50237 |
| Class: | Unknown |
| CVE: |
CVE-2011-3555 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2011 12:00AM |
| Updated: | Jul 24 2013 02:44PM |
| Credit: | Oracle |
| Vulnerable: |
VMWare VirtualCenter 2.5 VMWare vCenter 5.0 VMWare vCenter 4.1 VMWare vCenter 4.0 VMWare Update Manager 5.0 VMWare ESX 4.1 VMWare ESX 4.0 VMWare ESX 3.5 Sun JRE (Windows Production Release) 1.7 Sun JRE (Solaris Production Release) 1.7 Sun JRE (Linux Production Release) 1.7 Sun JDK (Windows Production Release) 1.7 Sun JDK (Solaris Production Release) 1.7 Sun JDK (Linux Production Release) 1.7 RedHat Enterprise Linux WS Extras 4 RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux ES Extras 4 RedHat Enterprise Linux AS Extras 4 RedHat Desktop Extras 4 Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux HPC Node Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client IBM Rational Policy Tester 8.5.0.1 IBM Rational Policy Tester 8.5 IBM Rational AppScan Standard 8.0.0.3 IBM Rational AppScan Standard 8.0.0 IBM Rational AppScan Standard 7.8 IBM Rational AppScan Enterprise 8.5.0.1 IBM Rational AppScan Enterprise 8.0.1.1 IBM Rational AppScan Enterprise 8.0.1 IBM Rational AppScan Enterprise 8.0.0.1 IBM Rational AppScan Enterprise 8.0.0 IBM Java SE 7.0 IBM Java SE 7 IBM Java SE 6 Gentoo Linux Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Application Server 5.2 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IR 4.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Interactive Response 4.0 Avaya CMS Server 16.2 Avaya CMS Server 16.1 Avaya CMS Server 16.0 Avaya CMS Server 15.0 AUX Avaya CMS Server 15.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
VMWare VirtualCenter 2.5 Update 6b VMWare Update Manager 5.0 Update 1 IBM Java SE 7 SR1 |
Discussion
Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'Java Runtime Environment' sub-component.
This vulnerability affects the following supported versions:
JDK and JRE 7
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'Java Runtime Environment' sub-component.
This vulnerability affects the following supported versions:
JDK and JRE 7
Exploit / POC
Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
References:
References:
- IBM Java Update Oracle February 14 2012 CPU (IBM)
- Oracle Critical Patch Updates (CPUs) and Synchronized Security Releases (SSRs) (IBM)
- ASA-2011-364 Oracle Java Critical Update Combined CVEs (October 2011) (Avaya)
- Oracle Java SE Critical Patch Update Advisory - October 2011 (Oracle)
- VMSA-2012-0003 VMware VirtualCenter Update and ESX 3.5 patch update JRE (VMware)
- VMSA-2012-0005 VMware vCenter Server, Orchestrator, Update Manager, vShield, vSp (VMware)