Skip to main content

Contrast CVE Shield

Contrast CVE Shield defends your applications against specific, known CVEs at runtime. Rather than detecting attack patterns, CVE Shield creates a precise containment boundary around the vulnerable code in a library.

If an attacker successfully triggers the vulnerability, CVE Shield blocks the exploit from reaching dangerous capabilities, such as starting a process, opening a network connection, or writing to the file system, while letting the library's normal, legitimate behavior continue unaffected.

CVE Shield is useful for the gap between a CVE being published and your team patching it. Instead of waiting on a patch cycle, CVE Shield gives you an immediate, evidence-based control: you can see whether a given CVE is being monitored or actively blocked in each of your environments.

Note

New to Contrast? See Try Contrast for free to sign up and install an agent to see your first vulnerabilities.

CVE Shield is available in Northstar on every Contrast plan and tier. Free-tier organizations can monitor or turn off monitoring. Block mode requires a paid tier.

CVE Shield currently supports Java applications only, and requires a minimum Java agent version of 6.33.1, or Flex Agent version 2.2.2 or later. If your agent doesn't meet this minimum, CVE Shield won't report status for that application. See Review Contrast CVE Shield states to learn more about CVE Shield status.

CVE Shield Free tier includes runtime CVE-related data only. Assess-generated vulnerability findings (e.g., SQL injection, custom-code data-flow vulnerabilities) require a paid tier. If you are looking to evaluate Assess/ADR, contact Contrast Security Sales at +1 888 371 1333.

Set and customize protection levels

Under Policies > CVE Shield, you can:

To see which CVEs in your application inventory have CVE Shield coverage today, and which don't, see View your CVE Shields in Explorer.

See also

Sign up for Contrast CVE Shield Free

View your CVE Shields in Explorer

Review Contrast CVE Shield states

Investigate with Explorer

View observations