Exposição de Java

Programming languages
30
score de exposição
269.966
sites usam
0
em exploração
0
críticos
Análise Vexday

Com 182 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, a taxa de exploração ativa do Java se mantém abaixo da média geral do catálogo, o que indica pressão reduzida de ataques confirmados no momento. O tipo de falha mais recorrente é CWE-327 (uso de algoritmos criptográficos quebrados ou de risco), sugerindo que fragilidades no suporte a primitivas criptográficas representam o padrão predominante de risco na tecnologia. O maior escore EPSS observado é de aproximadamente 0,376, associado a CVE-2019-2684, uma vulnerabilidade que, apesar de datar de 2019, ainda carrega probabilidade não desprezível de exploração e merece atenção em ambientes que ainda não aplicaram as devidas correções. A ausência de CVEs críticas ou novas nos últimos 90 dias pode refletir maturidade no ciclo de divulgação, mas não elimina a necessidade de revisão contínua, especialmente em implementações que dependem de algoritmos criptográficos legados.

CVEs

182 resultados
CVE-2017-10108Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that aEPSS 3.1%CVE-2017-10109Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that aEPSS 3.1%CVE-2020-2590LOWVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are JavEPSS 3.1%CVE-2020-14556MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are JaEPSS 3.0%CVE-2020-2593MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are JEPSS 3.0%CVE-2019-2449Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u19EPSS 3.0%CVE-2017-10118Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affecteEPSS 3.0%CVE-2017-10102Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are JavEPSS 3.0%CVE-2017-10346Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected areEPSS 3.0%CVE-2018-2639Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152EPSS 2.9%CVE-2019-2699Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affected is Java SE: 8u2EPSS 2.9%CVE-2020-2800MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are aEPSS 2.9%CVE-2017-10243Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affeEPSS 2.9%CVE-2018-3183Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are aEPSS 2.8%CVE-2017-3512Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8uEPSS 2.8%CVE-2018-2964Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172EPSS 2.8%CVE-2017-10115Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affecteEPSS 2.7%CVE-2019-2766Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected EPSS 2.7%CVE-2020-2816HIGHVulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. EEPSS 2.7%CVE-2019-2999Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221,EPSS 2.7%