支柱- a weakness that is the most abstract type of weakness and represents a theme for all class/base/variant weaknesses related to it. A Pillar is different from a Category as a Pillar is still technically a type of weakness that describes a mistake, while a Category represents a common characteristic used to group related things.
When a Servlet throws an exception, the default error response the Servlet container sends back to the user typically includes debugging information. This information is of great value to an attacker.
Potential Mitigations
Phase: Implementation
处理所有可能的情况(例如错误条件)。
Phase: Implementation
If an operation can throw an Exception, implement a handler for that specific exception.
[REF-62] Mark Dowd, John McDonald and Justin Schuh. "The Art of Software Security Assessment". Chapter 3, "File Handlers", Page 74. 1st Edition. Addison Wesley. 2006.
内容历史记录
Submissions
Submission Date
提交者
组织
2006-07-19
plover
修改
修改日期
Modifier
组织
2008-07-01
埃里克·达奇(Eric Dalci)
Cigital
更新的势_METIGATIONS,time_of_introduction
2008-09-08
CWE内容团队
MITER
更新的关系,其他_notes,分类_mappings
2009-05-27
CWE内容团队
MITER
updated Demonstrative_Examples
2010-12-13
CWE内容团队
MITER
updated Description, Other_Notes
2011-03-29
CWE内容团队
MITER
updated Demonstrative_Examples
2011-06-01
CWE内容团队
MITER
updated Common_Consequences
2011-06-27
CWE内容团队
MITER
updated Common_Consequences
2012-05-11
CWE内容团队
MITER
updated References, Relationships
2013-02-21
CWE内容团队
MITER
更新的势_MINEIGATIONS
2014-07-30
CWE内容团队
MITER
updated Relationships, Taxonomy_Mappings
2017-11-08
CWE内容团队
MITER
updated Applicable_Platforms
More information is available — Please select a different filter.