CVE-2017-10355: Medium severity oracle java se 7 vulnerability
An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Networking component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
Other sources
It was found that the FtpClient implementation in the Networking component of OpenJDK did not set connect and read timeouts by default. A malicious FTP server or a man-in-the-middle attacker could use this flaw to block execution of a Java application connecting to an FTP server.
— Red Hat
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-10355?
CVE-2017-10355 is an unspecified vulnerability in Oracle Java SE related to the Java SE Embedded JRockit Networking component.
Which versions of Java SE are affected by CVE-2017-10355?
Java SE versions 6u161, 7u151, 8u144, and 9 are affected by CVE-2017-10355.
How can an attacker exploit CVE-2017-10355?
An unauthenticated attacker can easily exploit CVE-2017-10355.
What is the severity rating of CVE-2017-10355?
CVE-2017-10355 has a severity rating of 5.3 (medium).
Where can I find more information about CVE-2017-10355?
You can find more information about CVE-2017-10355 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi/ftp:/example.com), [2](http://www.oracle.com/technetwork/java/javase/9-0-1-relnotes-3883752.html), [3](http://www.oracle.com/technetwork/java/javase/8u151-relnotes-3850493.html)