...
Leaving extra entry points into production code could allow an attacker to gain special access to the program.
Rule | Severity | Likelihood |
|---|
Detectable | Repairable | Priority | Level |
|---|---|---|---|
ENV06-J | High | Probable | No |
No |
P6 |
L2 |
Automated Detection
This rule is not amenable to automated static analysis.
| Tool | Version | Checker | Description |
|---|---|---|---|
| CodeSonar |
|
| JAVA.DEBUG.CEDF | Class enables debug features | |||||||
| Klocwork |
| JAVA.DEBUG.ENTRY | |||||||
| SonarQube |
|
|
| S2653 | Detects main in Servlet |
| s and EJBs |
Bibliography
...
...