Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Rules

Content by Label
showLabelsfalse
max99
spacescom.atlassian.confluence.content.render.xhtml.model.resource.identifiers.SpaceResourceIdentifier@3bbaf8c
showSpacefalse
sorttitle
cqllabel = "fio" and label = "rule" and label != "void" and space = currentSpace()
labels+fio, +rule, -void

Recommendations

FIO00-J. Validate deserialized objects

FIO01-J. Canonicalize path names originating from untrusted sources

FIO02-J. Use Runtime.exec() correctly

FIO04-J. Understand the limitations of the logging framework

FIO05-J. Document character encoding while performing file IO

FIO06-J. Validate user input

FIO07-J. Do not assume infinite heap space when reading in data

Rules

FIO31-J. Create a copy of mutable inputs

FIO32-J. Do not serialize sensitive data

FIO33-J. Do not allow serialization and deserialization to bypass the Security Manager

FIO34-J. Ensure all resources are properly closed when they are no longer needed

FIO35-J. Exclude user input from format strings

FIO36-J. Never hardcode sensitive information

Risk Assessment Summary

Recommendations

Recommendation Rule

Severity

Likelihood

Detectable

Repairable Remediation Cost

Priority

Level

FIO00-JMediumUnlikely medium probable No high No

P4 P2

L3

FIO01-JMediumProbable high probable No high No

P6 P4

L2 L3

FIO02-J -JMediumProbableYesYes

P12

L1

FIO03-JMediumProbableNoNo

P4

L3

FIO04-JLowProbableYesNo

P4

L3

FIO05-JMediumLikelyNoNo

high

probable

high

P6

L2

FIO06-JLowUnlikelyNoNo

P1

L3

FIO07-JLow medium Probable probable Yes high No

P4

L3

...

Rules Severity Likelihood Remediation Cost Priority Level
FIO08-JHighProbableYesYes

P18

L1 FIO31

FIO09-JLow medium Unlikely probable No high Yes

P4 P2

L3 FIO32

FIO10-JLowUnlikely medium likely No high No

P6 P1

L2 L3 FIO33

FIO12-JLow high Unlikely probable No high No

P6 P1

L2 L3 FIO35

FIO13-JMedium medium Probable probable No high No

P4

L3

FIO14-JMediumLikelyNoNo

P6

L2

FIO16-JMediumUnlikelyNoNo

P2

L3


...

Image Added Image Added Image AddedOBJ32-J. Do not allow partially initialized objects to be accessed      The CERT Sun Microsystems Secure Coding Standard for Java      FIO00-J. Validate deserialized objects