Umbra Wiki weakness weakness/CWE-600
Back to wiki

CWE-600 — Uncaught Exception in Servlet

provenance: imported · CWE: CWE-600

CWE-600: Uncaught Exception in Servlet

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit

Description

The Servlet does not catch all exceptions, which may reveal sensitive debugging information.

When a Servlet throws an exception, the default error response the Servlet container sends back to the user typically includes debugging information. This information is of great value to an attacker. For example, a stack trace might show the attacker a malformed SQL query string, the type of database being used, and the version of the application container. This information enables the attacker to target known vulnerabilities in these components.

Common consequences

  • Confidentiality, Availability: Read Application Data, DoS: Crash, Exit, or Restart

Mitigations

Implementation — Implement Exception blocks to handle all types of Exceptions.

References

  • CWE page: https://cwe.mitre.org/data/definitions/600.html
  • CWE list: https://cwe.mitre.org/data/index.html