VYPR
Unrated severityNVD Advisory· Published Oct 19, 2011· Updated Apr 29, 2026

CVE-2011-3549

CVE-2011-3549

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unspecified vulnerability in Oracle Java SE Swing component allows remote untrusted applets and Web Start applications to compromise confidentiality, integrity, and availability.

Vulnerability

An unspecified vulnerability exists in the Swing component of the Oracle Java Runtime Environment (JRE) and Java Development Kit (JDK). Affected versions include JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier [1][2][3][4]. The vulnerability is remotely exploitable by untrusted Java Web Start applications and untrusted Java applets via unknown vectors.

Exploitation

An attacker can exploit this vulnerability by hosting a malicious Java applet or Web Start application and enticing a user to run it in a vulnerable Java environment. No authentication is required, and the attack can be launched remotely over a network. The exact exploitation vectors are not disclosed.

Impact

Successful exploitation could allow an attacker to compromise the confidentiality, integrity, and availability of the affected system. This includes potential unauthorized information disclosure, modification of data, and denial of service. The impact is considered high, with CVSS base score of 10.0 as reported in HP security bulletins [4].

Mitigation

Oracle released fixes as part of the October 2011 Critical Patch Update. Users should upgrade to Java 6 Update 28, Java 5.0 Update 32, or Java 1.4.2_34 or later. HP has released security bulletins for HP-UX and HP Network Node Manager i (NNMi) recommending the application of the latest Java patches [1][2][3][4]. No workarounds are documented.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

214
  • Sun Corporation/Jdk93 versions
    cpe:2.3:a:sun:jdk:*:*:*:*:*:*:*:*+ 92 more
    • cpe:2.3:a:sun:jdk:*:*:*:*:*:*:*:*range: <=1.4.2_33
    • cpe:2.3:a:sun:jdk:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_1:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_10:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_11:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_12:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_13:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_14:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_15:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_16:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_17:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_18:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_19:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_2:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_20:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_21:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_22:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_23:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_24:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_25:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_26:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_27:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_28:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_29:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_3:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_30:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_31:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_32:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_4:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_5:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_6:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_7:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_8:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.4.2_9:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update11_b03:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update28:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update7_b03:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update8:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.5.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_22:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_23:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_24:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_25:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_26:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:*:update_27:*:*:*:*:*:*range: <=1.6.0
    • cpe:2.3:a:sun:jdk:*:update31:*:*:*:*:*:*range: <=1.5.0
  • Sun Corporation/Jre90 versions
    cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*+ 89 more
    • cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*range: <=1.4.2_33
    • cpe:2.3:a:sun:jre:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_14:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_15:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_16:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_17:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_18:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_19:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_20:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_21:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_22:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_23:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_24:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_25:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_26:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_27:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_28:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_29:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_30:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_31:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_32:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_22:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_23:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_24:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_25:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_26:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:*:update_27:*:*:*:*:*:*range: <=1.6.0
    • cpe:2.3:a:sun:jre:*:update31:*:*:*:*:*:*range: <=1.5.0
  • Range: 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier
  • osv-coords30 versions
    < 0.53.0-r0+ 29 more
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

20

News mentions

0

No linked articles in our index yet.