Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Finding the unknown versions of mx4j and sjsxp #367

Open
ananthram001 opened this issue Jun 6, 2024 · 4 comments
Open

Finding the unknown versions of mx4j and sjsxp #367

ananthram001 opened this issue Jun 6, 2024 · 4 comments
Labels
bug Something isn't working

Comments

@ananthram001
Copy link

ananthram001 commented Jun 6, 2024

I am using a security scanner in my application which is running on amazoncorretto:11.0.23-alpine3.18
when I see the internal image I can see its using amazon-coretto-11.

My scanner is reporting it has unknown versions of mx4j and sjsxp available.

I am not able to find the version nor able to find any documentation relevant to that. Please add relevant details.

Path showing are:
mx4j: usr/lib/jvm/java-11-amazon-corretto/jmods/java.management.jmod/classes/javax/management

sjsxp: usr/lib/jvm/java-11-amazon-corretto/jmods/java.xml.jmod/classes/com/sun

@ananthram001 ananthram001 added the bug Something isn't working label Jun 6, 2024
@Autumn808
Copy link
Contributor

We are looking into this thank you for the information.

@Autumn808
Copy link
Contributor

Would it be possible to get a reproducer and more information for to help us reproduce this to better help you?

@Autumn808
Copy link
Contributor

Also what type of scanner are you using?

@dvorarogawski
Copy link

Hi,

My security scanner is also picking up these 2 libraries and cannot find the version. The scanner is BlackDuck Binary Scanner.

usr/lib/jvm/java-11-amazon-corretto/jmods/java.management.jmod/classes/javax/management
Manifest File: var/lib/rpm/Packages

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants