对象已移动

可在此处找到该文档 Major security flaws in Java applications, European researchers warn – New Self New Life
New Self New Life
No Result
View All Result
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices
New Self New Life
No Result
View All Result
Home Softwares

Major security flaws in Java applications, European researchers warn

by admin
2 years ago
in Softwares
Major security flaws in Java applications, European researchers warn
Share on FacebookShare on Twitter


Major security flaws in Java applications, European researchers warn
Alexandre Bartel, Professor at Umeå College, has, in collaboration with European analysis colleagues, studied main weaknesses in one of many world’s largest programming languages. Credit score: Mattias Pettersson

Alexandre Bartel, Professor of Software program Engineering and Safety at Umeå College, in collaboration with a number of European researchers, has extensively analyzed weaknesses in software program written in one of many world’s most generally used programming languages.

“This includes flaws within the processes that retrieve and recreate data—corresponding to buyer accounts, transactions, or affected person information. These vulnerabilities can create large prices for companies, governments and public authorities.”

Java is behind purposes utilized in cellular video games, robots, embedded techniques or enterprise purposes. Through the years, a number of safety flaws have been reported and now European researchers have investigated whether or not and the way these have been addressed.

They’ve checked out Java merchandise that use deserialisation, the method of restoring packaged data to its earlier state, corresponding to consumer settings, sport features, procuring carts or banking purposes, and carried out an in-depth evaluation of current vulnerabilities and assaults.

Large firms affected

“We now have recognized weaknesses and the way they’ve been addressed. The issue is that the programmers appear to repeat the identical errors again and again and subsequently reintroduce the vulnerabilities,” Professor Bartel says.

Within the research “An In-Depth Examine of Java Deserialization Distant-Code Execution Exploits and Vulnerabilities,” which was performed in collaboration with Eric Bodden, Professor at Paderborn College, Yves Le Traon, Professor on the Université du Luxembourg and Imen Sayar, now researcher at INRIA, a number of examples are given:

  • Flaws in PayPal’s vital purposes—gave entry to manufacturing databases
  • Vulnerabilities on the San Francisco Division of Transportation—the attackers gained management of two,000 computer systems and blocked the cost techniques
  • Equifax, the biggest US credit score reporting company within the US—suffered an assault wherein the attacker managed to steal 147.7 million items of private information

What the European researchers are seeing is that the movement of bytes, the movement of data, opens for modification by attackers. “It’s in the course of the precise deserialization course of, when the knowledge is recreated, that the attacker can acquire complete management over the receiving system. Even very small adjustments within the code could make techniques weak to assaults,” Alexandre Bartel says.

Critical flaws

Most Java applications depend on exterior libraries and there’s no straightforward solution to repair the affected techniques. Alexandre Bartel argues that to stop safety flaws from being launched in new code, the builders ought to keep away from utilizing Java deserialisation altogether.

“Our findings recommend that the complete provide chain of the developed utility ought to be totally verified all through the appliance’s lifecycle. The findings are very severe as they’ve the potential to be pricey, not just for firms but in addition for society at giant,” says Alexandre Bartel.

The research has attracted appreciable curiosity and was printed within the extremely regarded and selective Transactions on Software program Engineering and Methodology journal, TOSEM, of the Affiliation of Computing Equipment, ACM. The findings have been additionally offered at ICSE, the Worldwide Convention on Software program Engineering, which is likely one of the most prestigious conferences within the subject.

Bartel and his analysis group are actually growing strategies to extra effectively detect these vulnerabilities and stop assaults.

Serialization and deserialisation

Processes in pc science that contain saving an information construction or object state in a format that may then be saved or transferred to a different computing surroundings. It includes “translating” information constructions right into a stream of bytes to facilitate storage in, for instance, a reminiscence, a file or throughout information switch to a different machine.

Examples embrace: Pharmaceutical techniques, the place governments require packaging to be coded in order that it may be tracked all through the availability chain. Recreation improvement: to retailer and cargo sport information corresponding to participant progress, settings and saved video games. Monetary sector: storage and transmission of information on monetary transactions between banks and different monetary techniques.

Offered by
Umea College

Quotation:
Main safety flaws in Java purposes, European researchers warn (2023, December 27)
retrieved 1 January 2024
from https://techxplore.com/information/2023-12-major-flaws-java-applications-european.html

This doc is topic to copyright. Aside from any truthful dealing for the aim of personal research or analysis, no
half could also be reproduced with out the written permission. The content material is offered for data functions solely.





Source link

Tags: ApplicationsEuropeanFlawsJavaMajorResearchersSecuritywarn
Previous Post

The One Thing Rachel Bolan Wants to Do Before Skid Row Is Done

Next Post

Zack Snyder Discusses the Vast Universe of His Netflix Sci-Fi Epic, Rebel Moon

Related Posts

Meta and UK Government launch ‘Open Source AI Fellowship’
Softwares

Meta and UK Government launch ‘Open Source AI Fellowship’

by admin
July 12, 2025
Supervised vs Unsupervised Learning: Machine Learning Overview
Softwares

Supervised vs Unsupervised Learning: Machine Learning Overview

by admin
July 10, 2025
Minor update (2) for Vivaldi Desktop Browser 7.5
Softwares

Minor update (2) for Vivaldi Desktop Browser 7.5

by admin
July 9, 2025
20+ Best Free Food Icon Sets for Designers — Speckyboy
Softwares

20+ Best Free Food Icon Sets for Designers — Speckyboy

by admin
July 8, 2025
Luna v1.0 & FlexQAOA bring constraint-aware quantum optimization to real-world problems
Softwares

Luna v1.0 & FlexQAOA bring constraint-aware quantum optimization to real-world problems

by admin
July 7, 2025
Next Post
Zack Snyder Discusses the Vast Universe of His Netflix Sci-Fi Epic, Rebel Moon

Zack Snyder Discusses the Vast Universe of His Netflix Sci-Fi Epic, Rebel Moon

Facts About His 7 Brothers and Sisters – Hollywood Life

Facts About His 7 Brothers and Sisters – Hollywood Life

  • Trending
  • Comments
  • Latest
Kanye West entry visa revoked by Australia after ‘Heil Hitler’ song release – National

Kanye West entry visa revoked by Australia after ‘Heil Hitler’ song release – National

July 3, 2025
CBackup Review: Secure and Free Online Cloud Backup Service

CBackup Review: Secure and Free Online Cloud Backup Service

September 18, 2021
Every Van Halen Album, Ranked 

Every Van Halen Album, Ranked 

August 12, 2024
I Tried Calocurb For 90 Days. Here’s My Review.

I Tried Calocurb For 90 Days. Here’s My Review.

January 8, 2025
Bones: All Of Brennan’s Interns, Ranked

Bones: All Of Brennan’s Interns, Ranked

June 15, 2021
Get to Know Ronnie Shacklett – Hollywood Life

Get to Know Ronnie Shacklett – Hollywood Life

December 6, 2023
5 ’90s Alternative Rock Bands That Should’ve Been Bigger

5 ’90s Alternative Rock Bands That Should’ve Been Bigger

April 13, 2025
Clevo CO Review – A Complete Company Details

Clevo CO Review – A Complete Company Details

January 19, 2024
Jeff Lynne Pulls Out of Final ELO Show — See His Statement

Jeff Lynne Pulls Out of Final ELO Show — See His Statement

July 12, 2025
Crypto Billionaire Justin Sun Buys Another $100 Million of Trump’s Memecoin

Crypto Billionaire Justin Sun Buys Another $100 Million of Trump’s Memecoin

July 12, 2025
Paris Haute Couture Week 2025 Best Looks

Paris Haute Couture Week 2025 Best Looks

July 12, 2025
It’s the last day to get up to 50 percent off air fryers, Instant Pots, blenders and more

It’s the last day to get up to 50 percent off air fryers, Instant Pots, blenders and more

July 11, 2025
Hey r/movies! We’re Courtney Stephens and Callie Hernandez, the filmmakers of the recent meta-fictional, experimental feature film INVENTION, that’s now streaming on Mubi. You might also know Callie from La La Land, Alien: Covenant, Blair Witch, Under the Silver Lake, The Endless. Ask us anything!

Hey r/movies! We’re Courtney Stephens and Callie Hernandez, the filmmakers of the recent meta-fictional, experimental feature film INVENTION, that’s now streaming on Mubi. You might also know Callie from La La Land, Alien: Covenant, Blair Witch, Under the Silver Lake, The Endless. Ask us anything!

July 12, 2025
Meta and UK Government launch ‘Open Source AI Fellowship’

Meta and UK Government launch ‘Open Source AI Fellowship’

July 12, 2025
Best Amazon Prime Day 2025 Alternative Sales: Walmart, Target & More

Best Amazon Prime Day 2025 Alternative Sales: Walmart, Target & More

July 11, 2025
Michael Strahan’s extended silence raises questions during GMA absence

Michael Strahan’s extended silence raises questions during GMA absence

July 11, 2025
New Self New Life

Your source for entertainment news, celebrities, celebrity news, and Music, Cinema, Digital Lifestyle and Social Media and More !

Categories

  • Celebrity
  • Cinema
  • Devices
  • Digital Lifestyle
  • Entertainment
  • Music
  • Social Media
  • Softwares
  • Uncategorized

Recent Posts

  • Jeff Lynne Pulls Out of Final ELO Show — See His Statement
  • Crypto Billionaire Justin Sun Buys Another $100 Million of Trump’s Memecoin
  • Paris Haute Couture Week 2025 Best Looks
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2021 New Self New Life.
New Self New Life is not responsible for the content of external sites. slotsfree  creator solana token

No Result
View All Result
  • Home
  • Entertainment
  • Celebrity
  • Cinema
  • Music
  • Digital Lifestyle
  • Social Media
  • Softwares
  • Devices

Copyright © 2021 New Self New Life.
New Self New Life is not responsible for the content of external sites.

New Self New Life