CVE-2010-3563

Exp

Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to "how Web Start retrieves security policies," BasicServiceImpl, and forged policies that bypass sandbox restrictions.

Published: 2010-10-19 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-3563 is rated High Exploit Risk (89.6/100): CVSS Critical severity, with high exploitation likelihood (EPSS 88.76%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-3563

EDB-ID Source Kind Published Link
16495 exploit_db edb 2011-01-22 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-3563

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-06-28 88.93% 88.76% -0.17%
2 2025-05-30 89.06% 88.93% -0.13%
3 2025-03-17 89.06%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-3563

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2010-3563

OS Trackers for CVE-2010-3563

vendor priority summary link
gentoo normal CVE-2010-3563: 1 GLSA(s) (201111-02), 3 atom(s) (app-emulation/emul-linux-x86-java, dev-java/sun-jdk, dev-java/sun-jre-bin); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-3563
redhat critical https://access.redhat.com/security/cve/CVE-2010-3563
suse high https://www.suse.com/security/cve/CVE-2010-3563/
ubuntu low CVE-2010-3563 low priority: Ubuntu including 1 source packages (sun-java6), 7 status rows across 7 suites (dapper, hardy, jaunty, karmic, lucid, maverick, upstream): released 5, DNE 1, needs-triage 1. https://ubuntu.com/security/CVE-2010-3563

Affected software / configurations for CVE-2010-3563

Vendor Product Version Raw CPE
sun jre <= 1.6.0 cpe:2.3:a:sun:jre:*:update_21:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
sun jdk <= 1.6.0 cpe:2.3:a:sun:jdk:*:update_21:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:*
sun jdk 1.6.0 cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*

References for CVE-2010-3563

URL Tags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/44954 Vendor Advisory
http://support.avaya.com/css/P8/documents/100114315
http://support.avaya.com/css/P8/documents/100123193
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0770.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0987.html
http://www.redhat.com/support/errata/RHSA-2011-0880.html Vendor Advisory
http://www.securityfocus.com/bid/43999
http://www.zerodayinitiative.com/advisories/ZDI-10-202/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12181
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12554
cvelogic Threat Intelligence