CVE-2008-5347: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow
infovulnerability
security
Summary
CVE-2008-5347 is a security flaw in Sun's Java Runtime Environment (JRE, the software that runs Java programs) version 6 Update 10 and earlier that allows untrusted applets (small Java programs) and applications to gain elevated privileges (special access rights) by exploiting weaknesses in the JAX-WS and JAXB packages (libraries used for web services and data processing). The vulnerability works through vectors (methods of attack) related to access to inner classes in these packages.
Vulnerability Details
CVSS Score
7.5
EPSS (30-day exploit probability)
EPSS: 2.8%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2008-5347
First tracked: February 15, 2026 at 08:42 PM
Classified by LLM (prompt v3) · confidence: 95%