{"id":"CVE-2011-3553","description":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.","cvssScore":3.5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":3.5,"vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2011-10-19","lastModified":"2026-06-16","affectedProducts":[{"vendor":"sun","product":"jdk","version":"1.7.0"},{"vendor":"sun","product":"jre","version":"1.7.0"},{"vendor":"oracle","product":"jrockit","versionEnd":"\u003c=r28.1.4"},{"vendor":"oracle","product":"jrockit","version":"r28.0.0"},{"vendor":"oracle","product":"jrockit","version":"r28.0.1"},{"vendor":"oracle","product":"jrockit","version":"r28.0.2"},{"vendor":"oracle","product":"jrockit","version":"r28.1.0"},{"vendor":"oracle","product":"jrockit","version":"r28.1.1"},{"vendor":"oracle","product":"jrockit","version":"r28.1.3"},{"vendor":"sun","product":"jdk","versionEnd":"\u003c=1.6.0","update":"update_27"},{"vendor":"sun","product":"jdk","version":"1.6.0"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_10"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_11"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_12"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_13"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_14"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_15"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_16"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_17"},{"vendor":"sun","product":"jdk","version":"1.6.0","update":"update_18"}],"totalAffectedProducts":3,"references":[{"url":"https://access.redhat.com/security/cve/CVE-2011-3553","source":"patch-hint","tags":["redhat-cve"]},{"url":"https://access.redhat.com/errata/RHSA-2011:1380","source":"redhat","tags":["ADVISORY","RHSA-2011:1380"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","source":"secalert_us@oracle.com"},{"url":"http://marc.info/?l=bugtraq\u0026m=132750579901589\u0026w=2","source":"secalert_us@oracle.com"},{"url":"http://marc.info/?l=bugtraq\u0026m=134254866602253\u0026w=2","source":"secalert_us@oracle.com"},{"url":"http://marc.info/?l=bugtraq\u0026m=134254957702612\u0026w=2","source":"secalert_us@oracle.com"},{"url":"http://osvdb.org/76512","source":"secalert_us@oracle.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1455.html","source":"secalert_us@oracle.com"},{"url":"http://secunia.com/advisories/48308","source":"secalert_us@oracle.com"},{"url":"http://security.gentoo.org/glsa/glsa-201406-32.xml","source":"secalert_us@oracle.com"}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"no-match"},{"rule":"cna-maven-package","stage":"scope","outcome":"no-match"},{"rule":"known-cpe-product","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Matches known products: sun/jdk, sun/jre, oracle/jrockit"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (redhat-cve tier): https://access.redhat.com/security/cve/CVE-2011-3553 (from RHSA-2011:1380)"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"withheld","detail":"CVE ships in Java SE CPU Oct 2011 (CPU) — Oracle treats it as urgent, so severity does not settle it"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"patchHintUrl":"https://access.redhat.com/security/cve/CVE-2011-3553","patchHintTier":"redhat-cve","affectedProducts":[{"vendor":"sun","product":"jdk","isKnown":true,"cpe":"cpe:2.3:a:sun:jdk:1.7.0:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"sun","product":"jre","isKnown":true,"cpe":"cpe:2.3:a:sun:jre:1.7.0:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"oracle","product":"jrockit","isKnown":true,"cpe":"cpe:2.3:a:oracle:jrockit:*:*:*:*:*:*:*:*","source":"yaml"}]},"oracleAdvisories":[{"advisory":"Java SE CPU Oct 2011","releaseType":"CPU","quarter":"2011-Q4","url":"https://www.oracle.com/security-alerts/javacpuoct2011.html","products":[{"product":"Oracle JDK, JRE and JRockit","component":"Java Runtime Environment","affectedVersions":"JDK and JRE 7, 6 Update 27 and before. JRockit R28.1.4 and before"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.02205,"percentile":0.81575},"ssvc":{"available":false},"patchHintUrl":"https://access.redhat.com/security/cve/CVE-2011-3553","patchHintTier":"redhat-cve"}