CVE-2017-10350: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions th
mediumvulnerability
A vulnerability in JAX-WS (a Java component for web services) affects Java SE versions 7u151, 8u144, and 9, allowing an attacker on the network to partially disable the service without needing to log in. This mainly impacts users running untrusted Java applications downloaded from the internet in sandboxed environments (isolated, restricted execution spaces), not servers running trusted administrator-installed code, with a severity rating of 5.3 out of 10.
5.3(medium)
EPSS: 0.7%
Original source: https://nvd.nist.gov/vuln/detail/CVE-2017-10350
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%