CVE-2017-10243: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported ve
mediumvulnerability
security
Summary
A vulnerability in Oracle Java SE's JAX-WS (Java API for XML Web Services, a tool for building web services) allows attackers to read some data they shouldn't access and partially disrupt service availability without needing to authenticate. The flaw affects multiple Java versions and can be exploited through web services or sandboxed Java applications (restricted programs running in isolated environments), with a CVSS score (severity rating) of 6.5 out of 10.
Vulnerability Details
CVSS Score
6.5(medium)
EPSS (30-day exploit probability)
EPSS: 0.9%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2017-10243
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%