Tomcat 5.5.9 - 6.0.0 High Priority
#Category Warning Package/Class Method
1MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.authenticator.SingleSignOn
2MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.Connector
3STYLEDLS_DEAD_LOCAL_STOREorg.apache.catalina.connector.RequestsetCharacterEncoding
4MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.Request
5MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.Request
6MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.Request
7MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.RequestFacade
8MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.Response
9MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.connector.ResponseFacade
10STYLEDLS_DEAD_LOCAL_STOREorg.apache.catalina.core.ApplicationFilterConfigsetFilterDef
11MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.core.ContainerBase
12MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.core.NamingContextListener
13MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddApplicationListener
14MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddApplicationParameter
15MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddConstraint
16MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddFilterMap
17MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddInstanceListener
18MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddSecurityRole
19MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddWatchedResource
20MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddWelcomeFile
21MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddWrapperLifecycle
22MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextaddWrapperListener
23MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveApplicationListener
24MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveApplicationParameter
25MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveConstraint
26MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveFilterMap
27MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveInstanceListener
28MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveSecurityRole
29MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveWatchedResource
30MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveWelcomeFile
31MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveWrapperLifecycle
32MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardContextremoveWrapperListener
33MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.core.StandardContext
34BAD_PRACTICESE_BAD_FIELDorg.apache.catalina.core.StandardContext
35BAD_PRACTICESE_BAD_FIELDorg.apache.catalina.core.StandardContext
36MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.core.StandardHostremoveAlias
37MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.core.StandardPipeline
38MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.loader.WebappClassLoader
39CORRECTNESSDMI_INVOKING_TOSTRING_ON_ARRAYorg.apache.catalina.realm.RealmBaseauthenticate
40MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.realm.RealmBase
41MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.servlets.DefaultServlet
42MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.servlets.DefaultServlet
43MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.JDBCStore
44MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.JDBCStore
45MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.ManagerBase
46MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.ManagerBase
47MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.PersistentManager
48CORRECTNESSMF_CLASS_MASKS_FIELDorg.apache.catalina.session.PersistentManagerBase
49MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.StandardManager
50MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.StandardSession
51CORRECTNESSSE_METHOD_MUST_BE_PRIVATEorg.apache.catalina.session.StandardSessionreadObject
52CORRECTNESSSE_METHOD_MUST_BE_PRIVATEorg.apache.catalina.session.StandardSessionwriteObject
53MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.StoreBase
54MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.session.StoreBase
55MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.ssi.SSIMediator
56MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.ContextConfig
57MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.ContextConfig
58MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.DigesterFactory
59MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.Embedded
60MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.HostConfig
61MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.startup.HostConfig
62STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.catalina.startup.TldConfigsetTldNamespaceAware
63STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.catalina.startup.TldConfigsetTldValidation
64MT_CORRECTNESSSTCAL_INVOKE_ON_STATIC_DATE_FORMAT_INSTANCEorg.apache.catalina.util.CookieToolsgetCookieHeaderValue
65MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.util.InstanceSupportaddInstanceListener
66MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.util.InstanceSupportremoveInstanceListener
67MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.util.LifecycleSupportaddLifecycleListener
68MT_CORRECTNESSML_SYNC_ON_FIELD_TO_GUARD_CHANGING_THAT_FIELDorg.apache.catalina.util.LifecycleSupportremoveLifecycleListener
69MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.util.Strftime
70BAD_PRACTICEHE_EQUALS_USE_HASHCODEorg.apache.catalina.util.URLequals
71CORRECTNESSNP_ALWAYS_NULLorg.apache.catalina.valves.AccessLogValvereplace
72MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.valves.ErrorReportValve
73MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.valves.RequestFilterValve
74MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.catalina.valves.ValveBase
75MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.coyote.http11.Http11Processor
76MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.coyote.http11.Http11Protocol
77MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.coyote.http11.Http11Protocol
78MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.coyote.http11.InternalInputBuffer
79MALICIOUS_CODEMS_MUTABLE_ARRAYorg.apache.jasper.Constants
80MALICIOUS_CODEMS_MUTABLE_ARRAYorg.apache.jasper.Constants
81MALICIOUS_CODEMS_MUTABLE_ARRAYorg.apache.jasper.Constants
82STYLEDLS_DEAD_LOCAL_STOREorg.apache.jasper.compiler.ParserparseAttributeDirective
83STYLEDLS_DEAD_LOCAL_STOREorg.apache.jasper.compiler.ParserparseVariableDirective
84MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.compiler.ServletWriter
85MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.compiler.ServletWriter
86CORRECTNESSIL_INFINITE_RECURSIVE_LOOPorg.apache.jasper.runtime.JspContextWrapperinclude
87MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.runtime.TagHandlerPool
88MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.runtime.TagHandlerPool
89MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.util.SystemLogHandler
90MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jasper.util.SystemLogHandler
91CORRECTNESSINT_BAD_COMPARISON_WITH_SIGNED_BYTEorg.apache.jasper.xmlparser.ASCIIReaderread
92STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.jk.apr.AprImpl
93CORRECTNESSDMI_INVOKING_TOSTRING_ON_ARRAYorg.apache.jk.common.ChannelSocketread
94CORRECTNESSMF_CLASS_MASKS_FIELDorg.apache.jk.common.JkMX
95CORRECTNESSDMI_INVOKING_TOSTRING_ON_ARRAYorg.apache.jk.common.MsgAjpdump
96MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.jk.server.JkCoyoteHandler
97STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.jk.server.JkMain
98MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.naming.ContextBindings
99BAD_PRACTICEDE_MIGHT_IGNOREorg.apache.naming.factory.SendMailFactory$1run
100BAD_PRACTICECN_IDIOM_NO_SUPER_CALLorg.apache.naming.resources.ResourceAttributesclone
101MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.IntrospectionUtils
102CORRECTNESSEQ_SELF_USE_OBJECTorg.apache.tomcat.util.buf.MessageBytesequals
103MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.buf.StringCache
104MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.buf.StringCache
105STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachereset
106STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachereset
107STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachesetByteEnabled
108STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachesetCacheSize
109STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachesetCharEnabled
110STYLEST_WRITE_TO_STATIC_FROM_INSTANCE_METHODorg.apache.tomcat.util.buf.StringCachesetTrainThreshold
111BAD_PRACTICEES_COMPARING_STRINGS_WITH_EQorg.apache.tomcat.util.digester.DigesterupdateBodyText
112MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.GenericParser
113MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.GenericParser
114CORRECTNESSNP_NULL_PARAM_DEREForg.apache.tomcat.util.digester.SetNextRuleend
115CORRECTNESSNP_NULL_PARAM_DEREForg.apache.tomcat.util.digester.SetRootRuleend
116CORRECTNESSNP_NULL_PARAM_DEREForg.apache.tomcat.util.digester.SetTopRuleend
117MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.XercesParser
118MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.XercesParser
119MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.XercesParser
120MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.digester.XercesParser
121MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.http.HttpMessages
122MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.http.MimeMap
123MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.log.SystemLogHandler
124MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.log.SystemLogHandler
125BAD_PRACTICEHE_EQUALS_USE_HASHCODEorg.apache.tomcat.util.net.URLequals
126MALICIOUS_CODEMS_SHOULD_BE_FINALorg.apache.tomcat.util.threads.ThreadWithAttributes
back