...
Rule | Severity | Likelihood | Remediation Cost | Priority | Level |
|---|---|---|---|---|---|
IDS07-J | High | Probable | Medium | P12 | L1 |
Automated Detection
| Tool | Version | Checker | Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Checker Framework |
| Tainting Checker | Trust and security errors (see Chapter 8) | |||||||||||||
| CodeSonar |
| JAVA.IO.INJ.COMMAND | Command Injection (Java) | |||||||||||||
| Coverity | 7.5 | OS_CMD_INJECTION | Implemented | |||||||||||||
| Klocwork |
| SV.EXEC SV.EXEC.DIR SV.EXEC.ENV SV.EXEC.LOCAL SV.EXEC.PATH | ||||||||||||||
| Parasoft Jtest |
| PORTCERT.IDS07.EXEC | Do not use 'Runtime.exec()' | |||||||||||||
| SonarQube | Java Plugin
| Java Plugin
| Java Plugin
| OS commands should not be vulnerable to injection attacks |
Related Vulnerabilities
CVE-2010-0886 | |
CVE-2010-1826 | Command injection in |
T-472 | Mac OS X Java Command Injection Flaw in |
...