CWE-382

J2EE Bad Practices: Use of System.exit()

Medium

Description

A J2EE application uses System.exit(), which also shuts down its container.

Potential Impact

How to Fix

Architecture and Design

The shutdown function should be a privileged function available only to a properly authorized administrative user

Implementation

Web applications should not call methods that cause the virtual machine to exit, such as System.exit()

Implementation

Web applications should also not throw any Throwables to the application server as this may adversely affect the container.

Implementation

Non-web applications may have a main() method that contains a System.exit(), but generally should not call System.exit() from other locations in the code

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-382 vulnerabilities in your codebase.

Get Security Assessment