peter bassill · operator
$ cve CVE-2017-10355 JSON

CVE-2017-10355 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 16.2% (pctl 97)

Patch early

A public exploit exists.

Description

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS16.18% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2017-10-19
Last modified2026-06-17

Affected (30)

VendorProduct
debiandebian linux
netappactive iq unified manager
netappcloud backup
netappe-series santricity management plug-ins
netappe-series santricity os controller
netappe-series santricity storage manager
netappe-series santricity web services
netappelement software
netapponcommand balance
netapponcommand insight
netapponcommand performance manager
netapponcommand shift
netapponcommand unified manager
netapponcommand workflow automation
netappplug-in for symantec netbackup
netappsnapmanager
netappsteelstore cloud integrated storage
netappstorage replication adapter for clustered data ontap
netappvasa provider for clustered data ontap
netappvirtual storage console
oraclejdk
oraclejre
oraclejrockit
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatsatellite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD