FAQ

  • The CVE Shield free tier initial release identifies and monitors Java vulnerabilities, including Log4Shell, Spring4Shell and Apache Commons Collections deserialization vulnerabilities. Contrast will expand coverage to additional high- and critical-severity CVEs, with new protections delivered continuously as vulnerabilities emerge. The product tour provides an interactive click-through experience that allows users a glimpse into the power of Contrast and highlights key features. This only takes a few minutes and requires no technical expertise, installations or downloads.

  • CVE Shield is an application security tool that deploys inside running applications without requiring code changes. It monitors for both standard and AI-generated CVE exploits, detecting when known vulnerabilities are exercised in third-party libraries. It allows security teams to identify active threats and provides evidence of vulnerability exploitation in production environments.
  • It operates within the application runtime to detect and block exploitation attempts against known vulnerabilities in third-party libraries. By analyzing the execution path, it allows legitimate library functions to proceed while blocking dangerous actions, effectively shielding the application without the need for traditional patching or code modifications.
  • The CVE Shield free tier includes the CVE ID, dynamic scoring for severity ratings, and affected library for each vulnerability. It also shows which application the issue was found in and when it was first detected, along with access to community support.
  • The free tier is limited to one user, supports up to two applications, and provides real-time monitoring in "observation mode" (no automated blocking). Access is provided exclusively through the Northstar UI, and it does not include SIEM integration or support for multiple hosts beyond the defined application limits.
  • Yes, the CVE Shield free tier is provided at no cost, with no credit card required and no long-term commitment. It is designed to allow developers and security teams to understand Contrast’s capabilities and test how it fits into their environment before moving toward a tailored proof-of-value or enterprise deployment.
  • After you experience CVE Shield free trial or the Product Tour, request a tailored session. The team will scope a proof-of-value in your environment, including any required instrumentation, security reviews and success criteria.

Ready to schedule a demo with an expert?

Get a tailored demo that addresses the attacks on your applications and APIs.

Book a demo