IBM’s vulnerability discovery clearinghouse has found and fixed more than 400 vulnerabilities in popular Java libraries, the company announced on Tuesday.
The Lightwell clearinghouse is also now generally available, IBM said, meaning that customers can request priority security reviews of specific open-source software vulnerabilities.
As AI has made it easier to discover and exploit vulnerabilities, the cybersecurity community has begun paying more attention to the risks of legacy and open-source software, which is rife with undiscovered flaws. Several nonprofit groups and vendors have created clearinghouses, including IBM’s Lightwell, the Linux Foundation’s Akrites and Chainguard’s Athena. The U.S. government has also launched a similar program.
The Java ecosystem that Lightwell analyzed is particularly perilous — and has been for many years. Nearly six in 10 Java services contain at least one exploitable vulnerability, the security firm Datadog said in a report released in February. The report also found that Java-based applications relied on third-party packages that were a median of almost 500 days behind their latest major version, suggesting that Java-based software heavily depends on outdated and possibly insecure code.
Lightwell’s discovery of hundreds of widespread Java vulnerabilities is a striking indicator of the insecurity of software supply chains. It also points to the inadequacy of existing oversight and transparency mechanisms, a problem that the government has been urging companies to address for the past decade.
“Even mature codebases require continued attention as threats evolve,” IBM said in a statement.
Lightwell and the other platforms use AI to help employees rapidly review large code bases and flag potential vulnerabilities. In Lightwell’s case, IBM said the system’s “powerful engine rapidly develops version-specific fixes for open-source application dependencies in production systems” and delivers the fixes to customers through securely maintained repositories.
IBM executives highlighted the importance of secure patch deployment that did not require customers to take affected systems offline.
“Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime,” Gunnar Hellekson, vice president and general manager of Lightwell for IBM’s Red Hat division, said in a statement.
