CVE-2017-10350: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions th
mediumvulnerability
security
Summary
A vulnerability in JAX-WS (a Java component for web services) affects Java SE versions 7u151, 8u144, and 9, allowing an attacker on the network to partially disable the service without needing to log in. This mainly impacts users running untrusted Java applications downloaded from the internet in sandboxed environments (isolated, restricted execution spaces), not servers running trusted administrator-installed code, with a severity rating of 5.3 out of 10.
Vulnerability Details
CVSS Score
5.3(medium)
EPSS (30-day exploit probability)
EPSS: 0.7%
Classification
Attack SophisticationModerate
Impact (CIA+S)
availability
Original source: https://nvd.nist.gov/vuln/detail/CVE-2017-10350
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%