Runtime Environment (ENV)
Rules
- ENV00-J. Do not sign code that performs only unprivileged operations
- ENV01-J. Place all security-sensitive code in a single JAR and sign and seal it
- ENV02-J. Do not trust the values of environment variables
- ENV03-J. Do not grant dangerous combinations of permissions
- ENV04-J. Do not disable bytecode verification
- ENV05-J. Do not deploy an application that can be remotely monitored
- ENV06-J. Production code must not contain debugging entry points
Risk Assessment Summary
| Rule | Severity | Likelihood | Detectable | Repairable | Priority | Level |
|---|---|---|---|---|---|---|
| ENV00-J | High | Probable | No | No | P6 | L2 |
| ENV01-J | High | Probable | No | No | P6 | L2 |
| ENV02-J | Low | Likely | Yes | No | P6 | L2 |
| ENV03-J | High | Likely | No | No | P9 | L2 |
| ENV04-J | High | Likely | No | No | P9 | L2 |
| ENV05-J | High | Probable | No | No | P6 | L2 |
| ENV06-J | High | Probable | No | No | P6 | L2 |


