Exposição de Java

Programming languages
30
score de exposição
269.966
sites usam
0
em exploração
0
críticos
Análise Vexday

Com 182 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, a taxa de exploração ativa do Java se mantém abaixo da média geral do catálogo, o que indica pressão reduzida de ataques confirmados no momento. O tipo de falha mais recorrente é CWE-327 (uso de algoritmos criptográficos quebrados ou de risco), sugerindo que fragilidades no suporte a primitivas criptográficas representam o padrão predominante de risco na tecnologia. O maior escore EPSS observado é de aproximadamente 0,376, associado a CVE-2019-2684, uma vulnerabilidade que, apesar de datar de 2019, ainda carrega probabilidade não desprezível de exploração e merece atenção em ambientes que ainda não aplicaram as devidas correções. A ausência de CVEs críticas ou novas nos últimos 90 dias pode refletir maturidade no ciclo de divulgação, mas não elimina a necessidade de revisão contínua, especialmente em implementações que dependem de algoritmos criptográficos legados.

CVEs

182 resultados
CVE-2020-2585MEDIUMVulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u231. DifficEPSS 3.3%CVE-2017-3526Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affectEPSS 3.3%CVE-2017-10348Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 3.3%CVE-2017-10357Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affectEPSS 3.3%CVE-2017-10349Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are JaEPSS 3.3%CVE-2017-10350Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are EPSS 3.3%CVE-2017-10281Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that aEPSS 3.3%CVE-2017-10067Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, EPSS 3.3%CVE-2020-14581LOWVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: EPSS 3.3%CVE-2020-14577LOWVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SEEPSS 3.3%CVE-2019-2978Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are JEPSS 3.3%CVE-2019-2988Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: EPSS 3.3%CVE-2019-2989Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are JEPSS 3.2%CVE-2017-10388Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 3.2%CVE-2019-2894Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are JavEPSS 3.2%CVE-2017-10342Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affeEPSS 3.1%CVE-2018-2940Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 3.1%CVE-2017-10285Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are JavEPSS 3.1%CVE-2017-10074Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected areEPSS 3.1%CVE-2017-10347Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are JaEPSS 3.1%