Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Guidelines

ENV00-J. Do not sign code that performs only unprivileged operations

ENV01-J. Place all privileged code in a single package and seal the package

ENV02-J. Create a secure sandbox using a Security Manager

ENV03-J. Never grant AllPermission to untrusted code

ENV04-J. Do not grant ReflectPermission with target suppressAccessChecks

ENV05-J. Do not grant RuntimePermission with target createClassLoader

ENV06-J. Provide a trusted environment and sanitize all inputs

ENV07-J. Do not deploy an application that can be accessed by the JVM Tool Interface

ENV08-J. Do not deploy an application that can be accessed using the Java Platform Debugger Architecture

ENV09-J. Limit remote uses of JVM Monitoring and Managing

...

Content by Label
showLabelsfalse
maxResults99
label+env,-void
showSpacefalse
sorttitle
space@self
cqllabel = "env" and label != "void" and space = currentSpace()

Risk Assessment Summary

Guideline

Severity

Likelihood

Remediation Cost

Priority

Level

ENV00-J

high

probable

medium

P12

L1

ENV01-J

high

probable

medium

P12

L1

ENV02-J

high

probable

low

P18

L1

ENV03-J

high

likely

low

P27

L1

ENV04-J

high

probable

low

P18

L1

ENV05-J

high

probable

low

P18

L1

ENV06-J

high

probable

medium

P12

L1

ENV07-J

low

unlikely

medium

P2

L3

ENV08-J

high

probable

medium

P12

L1

ENV09-J

high

probable

low

P18

L1

ENV10-J

high

likely

low

P27

L1

...