it's the java code in the applications that's being exploited, not the
underlying Linux code. Kind of like the work area around a minimum security prison, people can't sneak into the cells and admin area, but all sort of things can go on in the open grounds around it.