Oracle Java SE
cpe:2.3:a:oracle:java_se:*:*:*:*:*:*:*, +1 more
- <= 6u27
This vulnerability is being actively exploited in the wild.
A vulnerability has been identified in the Java Runtime Environment (JRE) component of Oracle Java SE JDK and JRE 6 Update 27 and earlier, as well as JDK and JRE 7. This vulnerability allows remote, untrusted Java Web Start applications and applets to execute arbitrary code, potentially leading to unauthorized actions on behalf of the user.
Exploitation of this vulnerability could result in arbitrary code execution on the affected system.
Users can upgrade to Oracle Java SE JDK and JRE 6 Update 31 or 7 Update 3. Instructions for downloading the latest Java SE release are available on the Oracle Java SE Downloads page. For Red Hat users, the updated java-1.6.0-ibm packages that fix this vulnerability are available through the Red Hat Network.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.