Exposure of Java

Programming languages
30
exposure score
269,966
sites use
0
exploited
0
critical
Vexday analysis

Com 182 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, a taxa de exploração ativa do Java se mantém abaixo da média geral do catálogo, o que indica pressão reduzida de ataques confirmados no momento. O tipo de falha mais recorrente é CWE-327 (uso de algoritmos criptográficos quebrados ou de risco), sugerindo que fragilidades no suporte a primitivas criptográficas representam o padrão predominante de risco na tecnologia. O maior escore EPSS observado é de aproximadamente 0,376, associado a CVE-2019-2684, uma vulnerabilidade que, apesar de datar de 2019, ainda carrega probabilidade não desprezível de exploração e merece atenção em ambientes que ainda não aplicaram as devidas correções. A ausência de CVEs críticas ou novas nos últimos 90 dias pode refletir maturidade no ciclo de divulgação, mas não elimina a necessidade de revisão contínua, especialmente em implementações que dependem de algoritmos criptográficos legados.

CVEs

182 results
CVE-2019-2958Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are JaEPSS 2.6%CVE-2017-10274Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6uEPSS 2.6%CVE-2019-2977Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.4 and 13EPSS 2.6%CVE-2019-2786Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected arEPSS 2.6%CVE-2017-10198Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are afEPSS 2.6%CVE-2017-10135Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affecteEPSS 2.6%CVE-2017-3533Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are EPSS 2.6%CVE-2019-2426Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201EPSS 2.6%CVE-2017-10087Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 2.6%CVE-2017-10096Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are JaEPSS 2.6%CVE-2017-10101Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are JaEPSS 2.6%CVE-2017-10107Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are JavEPSS 2.6%CVE-2017-10090Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 2.6%CVE-2017-3514Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u141, 7u131EPSS 2.5%CVE-2018-3157Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Sound). The supported version that is affected is Java SE: 11. DiffiEPSS 2.5%CVE-2017-10117Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affeEPSS 2.5%CVE-2020-2764LOWVulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is JEPSS 2.4%CVE-2017-10345Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that aEPSS 2.4%CVE-2017-10110Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u151, 7u141EPSS 2.4%CVE-2017-10089Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7EPSS 2.4%