Exposição de Java

Programming languages
30
score de exposição
269.966
sites usam
0
em exploração
0
críticos
Análise Vexday

Com 182 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, a taxa de exploração ativa do Java se mantém abaixo da média geral do catálogo, o que indica pressão reduzida de ataques confirmados no momento. O tipo de falha mais recorrente é CWE-327 (uso de algoritmos criptográficos quebrados ou de risco), sugerindo que fragilidades no suporte a primitivas criptográficas representam o padrão predominante de risco na tecnologia. O maior escore EPSS observado é de aproximadamente 0,376, associado a CVE-2019-2684, uma vulnerabilidade que, apesar de datar de 2019, ainda carrega probabilidade não desprezível de exploração e merece atenção em ambientes que ainda não aplicaram as devidas correções. A ausência de CVEs críticas ou novas nos últimos 90 dias pode refletir maturidade no ciclo de divulgação, mas não elimina a necessidade de revisão contínua, especialmente em implementações que dependem de algoritmos criptográficos legados.

CVEs

182 resultados
CVE-2018-2790LOWVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected arEPSS 5.1%CVE-2017-10176Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are afEPSS 5.0%CVE-2018-2826HIGHVulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. DEPSS 5.0%CVE-2020-2781MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SEEPSS 4.9%CVE-2020-2830MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are EPSS 4.9%CVE-2020-2604HIGHVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected arEPSS 4.9%CVE-2018-2815MEDIUMVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that aEPSS 4.8%CVE-2018-2582Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected areEPSS 4.7%CVE-2018-2618Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affecteEPSS 4.7%CVE-2018-2973Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are JaEPSS 4.7%CVE-2018-2678Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affectEPSS 4.7%CVE-2018-2663Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are aEPSS 4.7%CVE-2018-2677Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are JavEPSS 4.7%CVE-2018-2637Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affecteEPSS 4.6%CVE-2018-2634Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are JaEPSS 4.5%CVE-2019-2602Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected aEPSS 4.4%CVE-2019-2762Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected aEPSS 4.4%CVE-2019-2769Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected aEPSS 4.4%CVE-2020-14621MEDIUMVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SEEPSS 4.3%CVE-2020-14664HIGHVulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. DifficEPSS 4.2%