Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Guidelines

FIO00-J. Canonicalize path names before validating

...

FIO03-J. Specify the character encoding while performing file or network IO

...

FIO30-J. Do not log sensitive information

...

FIO37-J. Do not expose buffers created using the wrap() or duplicate() methods to untrusted code

Risk Assessment Summary

Recommendations

Recommendation

Severity

Likelihood

Remediation Cost

Priority

Level

FIO00- J

medium

unlikely

medium

P4

L3

FIO01- J

low

probable

medium

P4

L3

FIO02- J

low

unlikely

medium

P2

L3

FIO03- J

low

unlikely

medium

P2

L3

Rules

Rules

Severity

Likelihood

Remediation Cost

Priority

Level

FIO30- J

medium

probable

high

P4

L3

FIO31- J

medium

probable

high

P4

L3

FIO32- J

low

probable

medium

P4

L3

FIO33- J

medium

unlikely

medium

P4

L3

FIO34- J

high

probable

medium

P12

L1

FIO36- J

low

unlikely

medium

P2

L3

FIO37- J

medium

likely

low

P18

L1

...