Azul has updated its Vulnerability Detection solution to reduce false positives in Java vulnerability detection by up to 99%.
The update aims to flag vulnerabilities in code paths that are actively used in Java applications, preventing unnecessary alerts.
By curating a knowledge base mapping CVEs to runtime-used classes, Azul ensures accurate identification of vulnerable components in applications.
This approach helps in distinguishing between potentially vulnerable components in use and parts that are not activated, thereby minimizing wasted efforts on non-critical vulnerabilities.