IBM and Red Hat Remediate Over 400 Unknown Java Vulnerabilities, Launch Lightwell Clearinghouse

Business Wire··US·Read original
3▲1 ▼0Impact / 5
Summary · why it matters

IBM and Red Hat announced that their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries, and that Lightwell Clearinghouse is now generally available. The Clearinghouse gives enterprise customers a direct path to submit specific open source software dependencies for priority review and remediation. Through Lightwell, the two companies uncovered, remediated and backported fixes for the more than 400 previously unknown bugs in widely deployed, production-grade software, delivering version-specific patches through secured repositories that connect with customers' existing IT processes without replacing their current security scanners, software repositories, development pipelines or testing processes. Applicable fixes are contributed back to upstream open source projects under responsible disclosure protocols, with embargo protections maintained for Clearinghouse participants. Gunnar Hellekson, vice president and general manager of Lightwell at Red Hat, said AI agents have shifted the threat landscape by exploiting old dependencies at machine speed, and that finding and neutralizing 400-plus novel vulnerabilities so quickly shows how fast Lightwell can move.

Impact on assets 1

Quantum Computing▲
International Business Machines
IBM
▲ PositiveTechnologyrelevance

IBM's Lightwell initiative with Red Hat identified and remediated 400+ unknown Java vulnerabilities and launched the Lightwell Clearinghouse product.

Off-coverage companies 1

Red Hat, Inc.i
Private▲ PositiveTechnologyrelevance

Red Hat co-developed Lightwell, remediated 400+ novel Java vulnerabilities, and launched the generally available Lightwell Clearinghouse.