DependencyCheck
DependencyCheck copied to clipboard
False Positive on splat-sdk-0.0.40.jar
False positive on library splat-sdk-0.0.40.jar - reported as cpe:2.3:a:sun:sdk:0.0.40:::::::*
As per description , vulnerability is present in Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier
Without a packageUrl for this library we cannot fix it and suppression would be up to you, I cannot find where this library originates from.