DependencyCheck icon indicating copy to clipboard operation
DependencyCheck copied to clipboard

False Positive on limits-dp-java-client-1.4.jar

Open Anshu2405 opened this issue 3 years ago • 1 comments

False positive on library limits-dp-java-client-1.4.jar - reported as cpe:2.3:a:sun:sdk:1.4.0:::::::*

As per description , vulnerability is present in Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier

Anshu2405 avatar Dec 15 '21 14:12 Anshu2405

Without a packageUrl for this library we cannot fix it and suppression would be up to you, I cannot find where this library originates from.

aikebah avatar Jun 08 '22 15:06 aikebah