Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to "how Web Start retrieves security policies," BasicServiceImpl, and forged policies that bypass sandbox restrictions.
Use Sun vendor hub and Jre product page to widen CVE-2010-3563 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-5824, CVE-2013-5850 and CVE-2013-5832 for nearby disclosures in the same product family.