SpotBugs Bug Detector Report

The following document contains the results of SpotBugs

SpotBugs Version is 4.10.4

Threshold is medium

Effort is max

Summary

Classes Bugs Errors Missing Classes
542 687 0 0

Files

Class Bugs
psiprobe.AbstractTomcatContainer 8
psiprobe.ProbeConfig 2
psiprobe.ProbeConfigTest 1
psiprobe.ProbeServlet 3
psiprobe.Utils 7
psiprobe.beans.ClusterWrapperBean 2
psiprobe.beans.ClusterWrapperBeanTest 1
psiprobe.beans.ContainerListenerBean 2
psiprobe.beans.ContainerWrapperBean 3
psiprobe.beans.ContainerWrapperBeanTest 5
psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer 1
psiprobe.beans.JBossResourceResolverBean 2
psiprobe.beans.JBossResourceResolverBeanTest 1
psiprobe.beans.JBossResourceResolverBeanTest$TestableJBossResourceResolverBean 1
psiprobe.beans.LogResolverBean 4
psiprobe.beans.LogResolverBeanTest 5
psiprobe.beans.ResourceResolverBean 6
psiprobe.beans.ResourceResolverBeanTest 5
psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor 3
psiprobe.beans.ResourceResolverBeanTest$TestableResourceResolverBean 1
psiprobe.beans.RuntimeInfoAccessorBean 1
psiprobe.beans.RuntimeInfoAccessorBeanTest 4
psiprobe.beans.stats.collectors.AbstractStatsCollectorBean 2
psiprobe.beans.stats.listeners.AbstractStatsCollectionListener 2
psiprobe.beans.stats.listeners.AbstractStatsCollectionListenerTest 1
psiprobe.beans.stats.listeners.AbstractThresholdListener 1
psiprobe.beans.stats.listeners.FlapListenerTests 8
psiprobe.beans.stats.listeners.StatsCollectionEvent 3
psiprobe.beans.stats.listeners.ThresholdListenerTests 2
psiprobe.beans.stats.providers.AbstractSeriesProvider 1
psiprobe.beans.stats.providers.ConnectorSeriesProvider 1
psiprobe.beans.stats.providers.MultipleSeriesProvider 2
psiprobe.beans.stats.providers.MultipleSeriesProvider$Series 1
psiprobe.beans.stats.providers.StandardSeriesProvider 3
psiprobe.beans.stats.providers.StandardSeriesProviderTest 3
psiprobe.controllers.AbstractContextHandlerController 1
psiprobe.controllers.AbstractTomcatContainerController 1
psiprobe.controllers.BeanToXmlController 4
psiprobe.controllers.DecoratorController 5
psiprobe.controllers.RememberVisibilityController 1
psiprobe.controllers.RenderChartController 2
psiprobe.controllers.WhoisController 7
psiprobe.controllers.apps.AbstractNoSelfContextHandlerController 1
psiprobe.controllers.apps.AjaxReloadContextController 5
psiprobe.controllers.apps.AjaxToggleContextController 7
psiprobe.controllers.apps.AjaxUptimeController 1
psiprobe.controllers.apps.AllAppStatsController 4
psiprobe.controllers.apps.BaseGetApplicationController 2
psiprobe.controllers.apps.BaseReloadContextController 3
psiprobe.controllers.apps.BaseStartContextController 3
psiprobe.controllers.apps.BaseStopContextController 3
psiprobe.controllers.apps.BaseViewXmlConfController 3
psiprobe.controllers.apps.DownloadContextXmlConfController 1
psiprobe.controllers.apps.DownloadWebXmlConfController 1
psiprobe.controllers.apps.GetApplicationProcDetailsController 1
psiprobe.controllers.apps.GetApplicationRequestDetailsController 1
psiprobe.controllers.apps.GetApplicationRuntimeInfoController 1
psiprobe.controllers.apps.GetApplicationSummaryController 1
psiprobe.controllers.apps.ListAppAttributesController 3
psiprobe.controllers.apps.ListAppInitParamsController 3
psiprobe.controllers.apps.ListApplicationResourcesController 2
psiprobe.controllers.apps.ListWebappsController 5
psiprobe.controllers.apps.ReloadContextController 1
psiprobe.controllers.apps.ReloadSummaryContextController 1
psiprobe.controllers.apps.RemoveApplicationAttributeController 1
psiprobe.controllers.apps.StartContextController 1
psiprobe.controllers.apps.StartSummaryContextController 1
psiprobe.controllers.apps.StopContextController 1
psiprobe.controllers.apps.StopSummaryContextController 1
psiprobe.controllers.apps.ViewContextXmlConfController 1
psiprobe.controllers.apps.ViewWebXmlConfController 1
psiprobe.controllers.certificates.ListCertificatesController 4
psiprobe.controllers.certificates.SslHostConfigHelper 1
psiprobe.controllers.certificates.SslHostConfigInfoTest 1
psiprobe.controllers.cluster.BaseClusterStatsController 1
psiprobe.controllers.cluster.ClusterMembersStatsController 1
psiprobe.controllers.cluster.ClusterRequestsStatsController 1
psiprobe.controllers.cluster.ClusterStatsController 1
psiprobe.controllers.cluster.ClusterTrafficStatsController 1
psiprobe.controllers.connectors.BaseGetConnectorController 1
psiprobe.controllers.connectors.GetConnectorProcTimeController 1
psiprobe.controllers.connectors.GetConnectorRequestController 1
psiprobe.controllers.connectors.GetConnectorTrafficController 1
psiprobe.controllers.connectors.ListConnectorsController 5
psiprobe.controllers.connectors.ResetConnectorStatsController 1
psiprobe.controllers.connectors.ToggleConnectorStatusController 1
psiprobe.controllers.connectors.ZoomChartController 4
psiprobe.controllers.datasources.ListAllJdbcResourceGroupsController 2
psiprobe.controllers.datasources.ListAllJdbcResourcesController 2
psiprobe.controllers.datasources.ResetDataSourceController 5
psiprobe.controllers.deploy.BaseUndeployContextController 4
psiprobe.controllers.deploy.CopySingleFileController 17
psiprobe.controllers.deploy.DeployConfigController 1
psiprobe.controllers.deploy.DeployContextController 7
psiprobe.controllers.deploy.DeployController 4
psiprobe.controllers.deploy.UndeployContextController 1
psiprobe.controllers.deploy.UndeploySummaryContextController 1
psiprobe.controllers.deploy.UploadWarController 15
psiprobe.controllers.error.Error403Controller 6
psiprobe.controllers.error.Error404Controller 1
psiprobe.controllers.filters.ListAppFilterMapsController 2
psiprobe.controllers.filters.ListAppFiltersController 2
psiprobe.controllers.help.HelpApplicationsController 1
psiprobe.controllers.help.HelpDatasourceTestController 1
psiprobe.controllers.help.HelpDatasourcesController 1
psiprobe.controllers.help.HelpSessionSearchController 1
psiprobe.controllers.help.HelpThreads2Controller 1
psiprobe.controllers.help.HelpThreadsController 1
psiprobe.controllers.jsp.DiscardCompiledJspController 1
psiprobe.controllers.jsp.DisplayJspController 2
psiprobe.controllers.jsp.DownloadServletController 1
psiprobe.controllers.jsp.RecompileJspController 1
psiprobe.controllers.jsp.ViewServletSourceController 2
psiprobe.controllers.jsp.ViewSourceController 2
psiprobe.controllers.logs.ChangeLogLevelController 2
psiprobe.controllers.logs.DownloadLogController 1
psiprobe.controllers.logs.FollowController 2
psiprobe.controllers.logs.FollowedFileInfoController 2
psiprobe.controllers.logs.ListLogsController 3
psiprobe.controllers.logs.SetupFollowController 2
psiprobe.controllers.oshi.OshiController 11
psiprobe.controllers.oshi.OshiControllerTest 6
psiprobe.controllers.quickcheck.BaseTomcatAvailabilityController 5
psiprobe.controllers.quickcheck.TomcatAvailabilityController 1
psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest 4
psiprobe.controllers.quickcheck.TomcatAvailabilityXmlController 1
psiprobe.controllers.servlets.ListServletMapsController 2
psiprobe.controllers.servlets.ListServletsController 2
psiprobe.controllers.servlets.ServletsController 1
psiprobe.controllers.sessions.ExpireSessionController 1
psiprobe.controllers.sessions.ExpireSessionsController 1
psiprobe.controllers.sessions.ListSessionAttributesController 4
psiprobe.controllers.sessions.ListSessionsController 4
psiprobe.controllers.sessions.ListSessionsControllerTest 1
psiprobe.controllers.sessions.RemoveSessAttributeController 1
psiprobe.controllers.sql.CachedRecordSetController 7
psiprobe.controllers.sql.ConnectionTestController 9
psiprobe.controllers.sql.DataSourceTestController 8
psiprobe.controllers.sql.ExecuteSqlController 16
psiprobe.controllers.sql.ExecuteSqlControllerTest 8
psiprobe.controllers.sql.QueryHistoryController 2
psiprobe.controllers.sql.QueryHistoryItemController 3
psiprobe.controllers.sql.QueryHistoryItemControllerTest 2
psiprobe.controllers.system.AdviseGarbageCollectionController 4
psiprobe.controllers.system.BaseMemoryStatsController 1
psiprobe.controllers.system.BaseSysInfoController 5
psiprobe.controllers.system.MemoryStatsAjaxController 1
psiprobe.controllers.system.MemoryStatsController 1
psiprobe.controllers.system.OsInfoAjaxController 1
psiprobe.controllers.system.OsInfoController 1
psiprobe.controllers.system.SysInfoController 1
psiprobe.controllers.system.SysPropsController 1
psiprobe.controllers.threads.GetClassLoaderUrlsController 2
psiprobe.controllers.threads.ImplSelectorController 5
psiprobe.controllers.threads.KillThreadController 2
psiprobe.controllers.threads.ListSunThreadsController 2
psiprobe.controllers.threads.ListThreadPoolsController 2
psiprobe.controllers.threads.ListThreadsController 3
psiprobe.controllers.threads.ThreadStackController 3
psiprobe.controllers.truststore.TrustStoreController 3
psiprobe.controllers.wrapper.RestartJvmController 3
psiprobe.controllers.wrapper.StopJvmController 4
psiprobe.controllers.wrapper.ThreadDumpController 3
psiprobe.controllers.wrapper.WrapperInfoController 5
psiprobe.jfreechart.XYLine3DRenderer 2
psiprobe.jfreechart.XYLine3DRendererTest 14
psiprobe.jsp.AddQueryParamTagTest 1
psiprobe.jsp.OutTagTest 1
psiprobe.jsp.ParamToggleTagTest 1
psiprobe.jsp.VisualScoreTag 3
psiprobe.jsp.VisualScoreTagTest 9
psiprobe.jsp.VolumeTagTest 1
psiprobe.model.ApplicationResource 2
psiprobe.model.ApplicationSession 2
psiprobe.model.Connector 2
psiprobe.model.DataSourceInfoGroupTest 2
psiprobe.model.DisconnectedLogDestination 1
psiprobe.model.DisconnectedLogDestinationTest 7
psiprobe.model.SessionSearchInfo 6
psiprobe.model.SessionSearchInfoTest 4
psiprobe.model.SunThread 2
psiprobe.model.SystemInformation 2
psiprobe.model.SystemInformationTest 1
psiprobe.model.certificates.Cert 1
psiprobe.model.certificates.CertificateInfo 1
psiprobe.model.certificates.ConnectorInfo 1
psiprobe.model.certificates.SslHostConfigInfo 1
psiprobe.model.jmx.ThreadPoolObjectName 4
psiprobe.model.jsp.Item 2
psiprobe.model.sql.DataSourceTestInfo 3
psiprobe.model.sql.DataSourceTestInfoTest 1
psiprobe.model.stats.StatsCollection 3
psiprobe.model.wrapper.WrapperInfo 2
psiprobe.tokenizer.StringTokenizer 4
psiprobe.tokenizer.Tokenizer 2
psiprobe.tools.ApplicationUtils 5
psiprobe.tools.ApplicationUtilsTest 7
psiprobe.tools.AsyncSocketFactory 1
psiprobe.tools.AsyncSocketFactory$SocketRunnable 2
psiprobe.tools.AsyncSocketFactory$TimeoutRunnable 1
psiprobe.tools.BackwardsFileStream 1
psiprobe.tools.InstrumentsTests$1Child 1
psiprobe.tools.InstrumentsTests$1Container 1
psiprobe.tools.InstrumentsTests$1Parent 1
psiprobe.tools.InstrumentsTests$1SimpleData 2
psiprobe.tools.JmxTools 8
psiprobe.tools.JmxToolsTest 1
psiprobe.tools.LogOutputStream 7
psiprobe.tools.LogOutputStreamTest 7
psiprobe.tools.MailMessage 1
psiprobe.tools.ObjectWrapperTest 1
psiprobe.tools.SecurityUtils 1
psiprobe.tools.SimpleAccessor 5
psiprobe.tools.SimpleAccessorTest$Target 2
psiprobe.tools.SizeExpressionTests 8
psiprobe.tools.Whois$Response 1
psiprobe.tools.logging.DefaultAccessor 6
psiprobe.tools.logging.commons.AbstractLoggerAccessorVisitor 1
psiprobe.tools.logging.commons.CommonsLoggerAccessorTest$LoggerHolder 1
psiprobe.tools.logging.commons.GetAllDestinationsVisitor 1
psiprobe.tools.logging.jdk.Jdk14HandlerAccessor 2
psiprobe.tools.logging.jdk.Jdk14LoggerAccessor 2
psiprobe.tools.logging.jdk.Jdk14LoggerAccessorTest 1
psiprobe.tools.logging.jdk.Jdk14ManagerAccessor 1
psiprobe.tools.logging.jdk.JuliHandlerAccessorTest 1
psiprobe.tools.logging.log4j.Log4JAppenderAccessor 2
psiprobe.tools.logging.log4j.Log4JLoggerAccessor 1
psiprobe.tools.logging.log4j.Log4JManagerAccessor 2
psiprobe.tools.logging.log4j2.Log4J2AppenderAccessor 3
psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessor 2
psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessorTest 1
psiprobe.tools.logging.log4j2.Log4J2WebLoggerContextUtilsAccessor 1
psiprobe.tools.logging.logback.LogbackAppenderAccessor 2
psiprobe.tools.logging.logback.LogbackAppenderAccessorTest 6
psiprobe.tools.logging.logback.LogbackFactoryAccessor 2
psiprobe.tools.logging.logback.LogbackLoggerAccessor 1
psiprobe.tools.logging.logback13.Logback13AppenderAccessor 2
psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest 6
psiprobe.tools.logging.logback13.Logback13FactoryAccessor 5
psiprobe.tools.logging.logback13.Logback13LoggerAccessor 1
psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessor 3
psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest 6
psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackFactoryAccessor 2
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessor 2
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest 6
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor 4
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13LoggerAccessor 1
psiprobe.tools.url.UrlParser 3

psiprobe.AbstractTomcatContainer

Bug Category Details Line Priority
Method psiprobe.AbstractTomcatContainer.compileItem(String, Options, Context, JspRuntimeContext, Summary, URLClassLoader, int, boolean) accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 560 Medium
Class psiprobe.AbstractTomcatContainer uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 413 Medium
Class psiprobe.AbstractTomcatContainer uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 357 Medium
Method psiprobe.AbstractTomcatContainer.remove(String) appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 222 Medium
To prevent illegal usage, logger should be private field. Change this field (logger) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 111 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 396 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 439 Medium

psiprobe.ProbeConfig

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 196 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 219 Medium

psiprobe.ProbeConfigTest

Bug Category Details Line Priority
Class psiprobe.ProbeConfigTest defines List based fields but uses them like Sets PERFORMANCE DLC_DUBIOUS_LIST_COLLECTION 37 Medium

psiprobe.ProbeServlet

Bug Category Details Line Priority
psiprobe.ProbeServlet.getWrapper() may expose internal representation by returning ProbeServlet.wrapper MALICIOUS_CODE EI_EXPOSE_REP 48 Medium
psiprobe.ProbeServlet.setWrapper(Wrapper) may expose internal representation by storing an externally mutable object into ProbeServlet.wrapper MALICIOUS_CODE EI_EXPOSE_REP2 53 Medium
Possible null pointer dereference in psiprobe.ProbeServlet.getContainerWrapperBean() due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 101 Medium

psiprobe.Utils

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.Utils.delete(File) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 130 Medium
java/lang/StringBuilder.append(Ljava/lang/String;)Ljava/lang/StringBuilder; is potentially injected into an XML string in method psiprobe.Utils.highlightStream(String, InputStream, String, String). SECURITY POTENTIAL_XML_INJECTION 469 Medium
java/lang/StringBuilder.append(Ljava/lang/String;)Ljava/lang/StringBuilder; is potentially injected into an XML string in method psiprobe.Utils.highlightStream(String, InputStream, String, String). SECURITY POTENTIAL_XML_INJECTION 471 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 341 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 351 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 565 Medium
This method psiprobe.Utils.getJspEncoding(InputStream) continues a loop after finding an equality condition CORRECTNESS SLS_SUSPICIOUS_LOOP_SEARCH 288 Medium

psiprobe.beans.ClusterWrapperBean

Bug Category Details Line Priority
Method psiprobe.beans.ClusterWrapperBean.getCluster(String, String, boolean) excessively uses methods of another class STYLE CE_CLASS_ENVY 47-186 Medium
Method psiprobe.beans.ClusterWrapperBean.getCluster(String, String, boolean) uses instanceof on multiple types to arbitrate logic STYLE ITC_INHERITANCE_TYPE_CHECKING 154 Medium

psiprobe.beans.ClusterWrapperBeanTest

Bug Category Details Line Priority
Method psiprobe.beans.ClusterWrapperBeanTest.testGetClusterReturnsClusterWhenJmxPresent() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 67 Medium

psiprobe.beans.ContainerListenerBean

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 342 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 362 Medium

psiprobe.beans.ContainerWrapperBean

Bug Category Details Line Priority
Shared primitive variable "forceFirstAdapter" in one thread may not yield the value of the most recent write from another thread MT_CORRECTNESS AT_STALE_THREAD_WRITE_OF_PRIMITIVE 83 Medium
psiprobe.beans.ContainerWrapperBean.getTomcatContainer() may expose internal representation by returning ContainerWrapperBean.tomcatContainer MALICIOUS_CODE EI_EXPOSE_REP 147 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 117 Medium

psiprobe.beans.ContainerWrapperBeanTest

Bug Category Details Line Priority
Method psiprobe.beans.ContainerWrapperBeanTest.getDataSourcesAggregatesPrivateAndGlobalDataSources() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 258 Medium
Method psiprobe.beans.ContainerWrapperBeanTest.getDataSourcesAggregatesPrivateAndGlobalDataSources() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 259 Medium
Method psiprobe.beans.ContainerWrapperBeanTest.setTomcatContainer(ContainerWrapperBean, TomcatContainer) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 310 Medium
Write to static field psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer.lastWrapper from instance method psiprobe.beans.ContainerWrapperBeanTest.setWrapperInitializesAndUnregistersSelectedAdapter() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 281 High
Write to static field psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer.setWrapperCalls from instance method psiprobe.beans.ContainerWrapperBeanTest.setWrapperInitializesAndUnregistersSelectedAdapter() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 282 High

psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer

Bug Category Details Line Priority
Write to static field psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer.lastWrapper from instance method psiprobe.beans.ContainerWrapperBeanTest$RecordingTomcatContainer.setWrapper(Wrapper) STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 46 Medium

psiprobe.beans.JBossResourceResolverBean

Bug Category Details Line Priority
Method psiprobe.beans.JBossResourceResolverBean.resetResource(Context, String, ContainerWrapperBean) throws alternative exception from catch block without history CORRECTNESS LEST_LOST_EXCEPTION_STACK_TRACE 179 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 178 Medium

psiprobe.beans.JBossResourceResolverBeanTest

Bug Category Details Line Priority
The use of DocumentBuilder.parse(...) (DocumentBuilder) is vulnerable to XML External Entity attacks SECURITY XXE_DOCUMENT 170 Medium

psiprobe.beans.JBossResourceResolverBeanTest$TestableJBossResourceResolverBean

Bug Category Details Line Priority
psiprobe.beans.JBossResourceResolverBeanTest$TestableJBossResourceResolverBean.getMBeanServer() may expose internal representation by returning JBossResourceResolverBeanTest$TestableJBossResourceResolverBean.server MALICIOUS_CODE EI_EXPOSE_REP 183 Medium

psiprobe.beans.LogResolverBean

Bug Category Details Line Priority
psiprobe.beans.LogResolverBean.getStdoutFiles() may expose internal representation by returning LogResolverBean.stdoutFiles MALICIOUS_CODE EI_EXPOSE_REP 82 Medium
psiprobe.beans.LogResolverBean.setStdoutFiles(List) may expose internal representation by storing an externally mutable object into LogResolverBean.stdoutFiles MALICIOUS_CODE EI_EXPOSE_REP2 93 Medium
Method psiprobe.beans.LogResolverBean.interrogateContext(Context, List) allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 330 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 351 Medium

psiprobe.beans.LogResolverBeanTest

Bug Category Details Line Priority
Method psiprobe.beans.LogResolverBeanTest.testGetLogDestination_Stdout() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 98 Medium
Method psiprobe.beans.LogResolverBeanTest.testGetLogDestinations_Empty() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 63 Medium
Method psiprobe.beans.LogResolverBeanTest.testGetLogDestinations_NullContextLoader() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 137 Medium
Method psiprobe.beans.LogResolverBeanTest.testGetLogSources_Empty() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 87 Medium
Method psiprobe.beans.LogResolverBeanTest.testGetLogSourcesByFile() appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 78 Medium

psiprobe.beans.ResourceResolverBean

Bug Category Details Line Priority
This use of javax/naming/Context.lookup(Ljava/lang/String;)Ljava/lang/Object; can be vulnerable to LDAP injection SECURITY LDAP_INJECTION 229 Medium
This use of javax/naming/Context.lookup(Ljava/lang/String;)Ljava/lang/Object; can be vulnerable to LDAP injection SECURITY LDAP_INJECTION 156 Medium
This use of javax/naming/Context.lookup(Ljava/lang/String;)Ljava/lang/Object; can be vulnerable to LDAP injection SECURITY LDAP_INJECTION 199 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 114 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 206 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 313 Medium

psiprobe.beans.ResourceResolverBeanTest

Bug Category Details Line Priority
Method psiprobe.beans.ResourceResolverBeanTest.getApplicationResourcesForContextBindsLooksUpAndUnbinds() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 95 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.resetToReturn from instance method psiprobe.beans.ResourceResolverBeanTest.resetResourceUsesDatasourceAccessorForGlobalResource() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 126 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.infoToReturn from instance method psiprobe.beans.ResourceResolverBeanTest.setUp() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 51 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.lastResource from instance method psiprobe.beans.ResourceResolverBeanTest.setUp() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 53 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.resetToReturn from instance method psiprobe.beans.ResourceResolverBeanTest.setUp() STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 52 Medium

psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor

Bug Category Details Line Priority
psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.getInfo(Object) may expose internal representation by returning ResourceResolverBeanTest$TestDatasourceAccessor.infoToReturn MALICIOUS_CODE EI_EXPOSE_REP 179 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.lastResource from instance method psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.getInfo(Object) STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 178 Medium
Write to static field psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.lastResource from instance method psiprobe.beans.ResourceResolverBeanTest$TestDatasourceAccessor.reset(Object) STYLE ST_WRITE_TO_STATIC_FROM_INSTANCE_METHOD 184 Medium

psiprobe.beans.ResourceResolverBeanTest$TestableResourceResolverBean

Bug Category Details Line Priority
psiprobe.beans.ResourceResolverBeanTest$TestableResourceResolverBean.getMBeanServer() may expose internal representation by returning ResourceResolverBeanTest$TestableResourceResolverBean.mbeanServer MALICIOUS_CODE EI_EXPOSE_REP 206 Medium

psiprobe.beans.RuntimeInfoAccessorBean

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 84 Medium

psiprobe.beans.RuntimeInfoAccessorBeanTest

Bug Category Details Line Priority
Method psiprobe.beans.RuntimeInfoAccessorBeanTest.testGetRuntimeInformation_IbmVendor() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 131 Medium
Method psiprobe.beans.RuntimeInfoAccessorBeanTest.testGetRuntimeInformation_IbmVendor() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 133 Medium
Method psiprobe.beans.RuntimeInfoAccessorBeanTest.testGetRuntimeInformation_NonIbmVendor() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 71 Medium
Method psiprobe.beans.RuntimeInfoAccessorBeanTest.testGetRuntimeInformation_NonIbmVendor() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 73 Medium

psiprobe.beans.stats.collectors.AbstractStatsCollectorBean

Bug Category Details Line Priority
psiprobe.beans.stats.collectors.AbstractStatsCollectorBean.getListeners() may expose internal representation by returning AbstractStatsCollectorBean.listeners MALICIOUS_CODE EI_EXPOSE_REP 71 Medium
psiprobe.beans.stats.collectors.AbstractStatsCollectorBean.setListeners(List) may expose internal representation by storing an externally mutable object into AbstractStatsCollectorBean.listeners MALICIOUS_CODE EI_EXPOSE_REP2 80 Medium

psiprobe.beans.stats.listeners.AbstractStatsCollectionListener

Bug Category Details Line Priority
Empty method psiprobe.beans.stats.listeners.AbstractStatsCollectionListener.reset() could be declared abstract STYLE ACEM_ABSTRACT_CLASS_EMPTY_METHODS 119 Medium
To prevent illegal usage, logger should be private field. Change this field (logger) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium

psiprobe.beans.stats.listeners.AbstractStatsCollectionListenerTest

Bug Category Details Line Priority
JUnit test method psiprobe.beans.stats.listeners.AbstractStatsCollectionListenerTest.testSetEnabled() passes boolean expression to Assert.assertFalse / Assert.assertTrue CORRECTNESS UTAO_JUNIT_ASSERTION_ODDITIES_USE_ASSERT_NOT_EQUALS 73 Medium

psiprobe.beans.stats.listeners.AbstractThresholdListener

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 145 Medium

psiprobe.beans.stats.listeners.FlapListenerTests

Bug Category Details Line Priority
Instance field psiprobe.beans.stats.listeners.FlapListenerTests.defaultInterval likely could be defined as static CORRECTNESS SPP_FIELD_COULD_BE_STATIC Not available Medium
Instance field psiprobe.beans.stats.listeners.FlapListenerTests.defaultThreshold likely could be defined as static CORRECTNESS SPP_FIELD_COULD_BE_STATIC Not available Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultHighWeight; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 37 Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultInterval; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 25 Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultLowWeight; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 34 Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultStartThreshold; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 28 Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultStopThreshold; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 31 Medium
Unread field: psiprobe.beans.stats.listeners.FlapListenerTests.defaultThreshold; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 22 Medium

psiprobe.beans.stats.listeners.StatsCollectionEvent

Bug Category Details Line Priority
psiprobe.beans.stats.listeners.StatsCollectionEvent.getData() may expose internal representation by returning StatsCollectionEvent.data MALICIOUS_CODE EI_EXPOSE_REP 79 Medium
new psiprobe.beans.stats.listeners.StatsCollectionEvent(String, XYDataItem) may expose internal representation by storing an externally mutable object into StatsCollectionEvent.data MALICIOUS_CODE EI_EXPOSE_REP2 41 Medium
psiprobe.beans.stats.listeners.StatsCollectionEvent.setData(XYDataItem) may expose internal representation by storing an externally mutable object into StatsCollectionEvent.data MALICIOUS_CODE EI_EXPOSE_REP2 88 Medium

psiprobe.beans.stats.listeners.ThresholdListenerTests

Bug Category Details Line Priority
Instance field psiprobe.beans.stats.listeners.ThresholdListenerTests.defaultThreshold likely could be defined as static CORRECTNESS SPP_FIELD_COULD_BE_STATIC Not available Medium
Unread field: psiprobe.beans.stats.listeners.ThresholdListenerTests.defaultThreshold; should this field be static? PERFORMANCE SS_SHOULD_BE_STATIC 22 Medium

psiprobe.beans.stats.providers.AbstractSeriesProvider

Bug Category Details Line Priority
To prevent illegal usage, logger should be private field. Change this field (logger) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium

psiprobe.beans.stats.providers.ConnectorSeriesProvider

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 50 Medium

psiprobe.beans.stats.providers.MultipleSeriesProvider

Bug Category Details Line Priority
Shared primitive variable "movingAvgFrame" in one thread may not yield the value of the most recent write from another thread MT_CORRECTNESS AT_STALE_THREAD_WRITE_OF_PRIMITIVE 98 Medium
Shared primitive variable "top" in one thread may not yield the value of the most recent write from another thread MT_CORRECTNESS AT_STALE_THREAD_WRITE_OF_PRIMITIVE 77 Medium

psiprobe.beans.stats.providers.MultipleSeriesProvider$Series

Bug Category Details Line Priority
The lock object psiprobe.beans.stats.providers.MultipleSeriesProvider$Series.stats used in method psiprobe.beans.stats.providers.MultipleSeriesProvider$Series.calculateAvg() is visible outside the class, thus exposing class psiprobe.beans.stats.providers.MultipleSeriesProvider$Series. SECURITY USO_UNSAFE_OBJECT_SYNCHRONIZATION 169-191 Medium

psiprobe.beans.stats.providers.StandardSeriesProvider

Bug Category Details Line Priority
psiprobe.beans.stats.providers.StandardSeriesProvider.getStatNames() may expose internal representation by returning StandardSeriesProvider.statNames MALICIOUS_CODE EI_EXPOSE_REP 40 Medium
psiprobe.beans.stats.providers.StandardSeriesProvider.setStatNames(List) may expose internal representation by storing an externally mutable object into StandardSeriesProvider.statNames MALICIOUS_CODE EI_EXPOSE_REP2 49 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 60 Medium

psiprobe.beans.stats.providers.StandardSeriesProviderTest

Bug Category Details Line Priority
Method psiprobe.beans.stats.providers.StandardSeriesProviderTest.testPopulateMissingStats() builds a list from one element using Arrays.asList rather than Collections.singletonList CORRECTNESS LUI_USE_SINGLETON_LIST 111 Medium
Method psiprobe.beans.stats.providers.StandardSeriesProviderTest.testPopulateWithSeriesParam() builds a list from one element using Arrays.asList rather than Collections.singletonList CORRECTNESS LUI_USE_SINGLETON_LIST 78 Medium
Method psiprobe.beans.stats.providers.StandardSeriesProviderTest.testPopulateWithStaticStatName() builds a list from one element using Arrays.asList rather than Collections.singletonList CORRECTNESS LUI_USE_SINGLETON_LIST 61 Medium

psiprobe.controllers.AbstractContextHandlerController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.AbstractContextHandlerController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 41 Medium

psiprobe.controllers.AbstractTomcatContainerController

Bug Category Details Line Priority
To prevent illegal usage, logger should be private field. Change this field (logger) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium

psiprobe.controllers.BeanToXmlController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.BeanToXmlController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 76 Medium
Possible null pointer dereference in psiprobe.controllers.BeanToXmlController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 73 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 63 High
Method psiprobe.controllers.BeanToXmlController.setXmlMarker(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 56 Medium

psiprobe.controllers.DecoratorController

Bug Category Details Line Priority
Method psiprobe.controllers.DecoratorController.handleRequestInternal(HttpServletRequest, HttpServletResponse) calls InetAddress.getLocalHost(), which may be a security risk CORRECTNESS MDM_INETADDRESS_GETLOCALHOST 70 Medium
Possible null pointer dereference in psiprobe.controllers.DecoratorController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 76 Medium
Possible null pointer dereference in psiprobe.controllers.DecoratorController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 85 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 62 High
Method psiprobe.controllers.DecoratorController.setMessagesBasename(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 55 Medium

psiprobe.controllers.RememberVisibilityController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 40 High

psiprobe.controllers.RenderChartController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.RenderChartController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 128 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 72 High

psiprobe.controllers.WhoisController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 132 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 154 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 116 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 157 Medium
Method psiprobe.controllers.WhoisController.setDefaultPort(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 109 Medium
Method psiprobe.controllers.WhoisController.setDefaultServer(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 90 Medium
Method psiprobe.controllers.WhoisController.setLookupTimeout(long) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 71 Medium

psiprobe.controllers.apps.AbstractNoSelfContextHandlerController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.AbstractNoSelfContextHandlerController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 63 Medium

psiprobe.controllers.apps.AjaxReloadContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.AjaxReloadContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 55 Medium
Possible null pointer dereference in psiprobe.controllers.apps.AjaxReloadContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 56 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 56 High
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 63 Medium

psiprobe.controllers.apps.AjaxToggleContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.AjaxToggleContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 53 Medium
Possible null pointer dereference in psiprobe.controllers.apps.AjaxToggleContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 57 Medium
Possible null pointer dereference in psiprobe.controllers.apps.AjaxToggleContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 62 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 57 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 62 High
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 70 Medium

psiprobe.controllers.apps.AjaxUptimeController

Bug Category Details Line Priority
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 54 Medium

psiprobe.controllers.apps.AllAppStatsController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.AllAppStatsController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 71 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 65 High
Method psiprobe.controllers.apps.AllAppStatsController.setCollectionPeriod(long) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 48 Medium
Method psiprobe.controllers.apps.AllAppStatsController.setCollectionPeriod(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 58 Medium

psiprobe.controllers.apps.BaseGetApplicationController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.BaseGetApplicationController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 84 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 95 Medium

psiprobe.controllers.apps.BaseReloadContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.BaseReloadContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 36 Medium
Possible null pointer dereference in psiprobe.controllers.apps.BaseReloadContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 37 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 37 High

psiprobe.controllers.apps.BaseStartContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.BaseStartContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 33 Medium
Possible null pointer dereference in psiprobe.controllers.apps.BaseStartContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 34 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 34 High

psiprobe.controllers.apps.BaseStopContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.BaseStopContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 33 Medium
Possible null pointer dereference in psiprobe.controllers.apps.BaseStopContextController.executeAction(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 34 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 34 High

psiprobe.controllers.apps.BaseViewXmlConfController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.BaseViewXmlConfController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 106 Medium
Possible null pointer dereference in psiprobe.controllers.apps.BaseViewXmlConfController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 115 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 99 Medium

psiprobe.controllers.apps.DownloadContextXmlConfController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.DownloadWebXmlConfController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.GetApplicationProcDetailsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.GetApplicationRequestDetailsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.GetApplicationRuntimeInfoController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.GetApplicationSummaryController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.apps.ListAppAttributesController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.ListAppAttributesController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 49 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 47 Medium

psiprobe.controllers.apps.ListAppInitParamsController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.apps.ListAppInitParamsController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 45 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 36 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 44 Medium

psiprobe.controllers.apps.ListApplicationResourcesController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 34 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 42 Medium

psiprobe.controllers.apps.ListWebappsController

Bug Category Details Line Priority
Do not catch NullPointerException like in psiprobe.controllers.apps.ListWebappsController.handleRequestInternal(HttpServletRequest, HttpServletResponse) STYLE DCN_NULLPOINTER_EXCEPTION 54 Medium
Possible null pointer dereference in psiprobe.controllers.apps.ListWebappsController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 49 Medium
Possible null pointer dereference in psiprobe.controllers.apps.ListWebappsController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 56 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 70 Medium

psiprobe.controllers.apps.ReloadContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.ReloadSummaryContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.RemoveApplicationAttributeController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 36 High

psiprobe.controllers.apps.StartContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.StartSummaryContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.StopContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.StopSummaryContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.ViewContextXmlConfController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.apps.ViewWebXmlConfController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.certificates.ListCertificatesController

Bug Category Details Line Priority
Method psiprobe.controllers.certificates.ListCertificatesController.toConnectorInfo(AbstractHttp11Protocol) uses a Side Effect Constructor STYLE SEC_SIDE_EFFECT_CONSTRUCTOR 247 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 63 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 70 Medium
This web server request could be used by an attacker to expose internal services and filesystem. SECURITY URLCONNECTION_SSRF_FD 223 Medium

psiprobe.controllers.certificates.SslHostConfigHelper

Bug Category Details Line Priority
Exception thrown in class psiprobe.controllers.certificates.SslHostConfigHelper at new psiprobe.controllers.certificates.SslHostConfigHelper(AbstractHttp11Protocol, ConnectorInfo) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 46 Medium

psiprobe.controllers.certificates.SslHostConfigInfoTest

Bug Category Details Line Priority
Hard coded password found SECURITY HARD_CODE_PASSWORD 57 Medium

psiprobe.controllers.cluster.BaseClusterStatsController

Bug Category Details Line Priority
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 82 Medium

psiprobe.controllers.cluster.ClusterMembersStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.cluster.ClusterRequestsStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High

psiprobe.controllers.cluster.ClusterStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 49 High

psiprobe.controllers.cluster.ClusterTrafficStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High

psiprobe.controllers.connectors.BaseGetConnectorController

Bug Category Details Line Priority
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 51 Medium

psiprobe.controllers.connectors.GetConnectorProcTimeController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.connectors.GetConnectorRequestController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.connectors.GetConnectorTrafficController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.connectors.ListConnectorsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 97 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 115 Medium
Method psiprobe.controllers.connectors.ListConnectorsController.setCollectionPeriod(long) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 61 Medium
Method psiprobe.controllers.connectors.ListConnectorsController.setCollectionPeriod(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 71 Medium
Method psiprobe.controllers.connectors.ListConnectorsController.setIncludeRequestProcessors(boolean) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 90 Medium

psiprobe.controllers.connectors.ResetConnectorStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High

psiprobe.controllers.connectors.ToggleConnectorStatusController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 52 High

psiprobe.controllers.connectors.ZoomChartController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.connectors.ZoomChartController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 71 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 65 High
Method psiprobe.controllers.connectors.ZoomChartController.setCollectionPeriod(long) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 48 Medium
Method psiprobe.controllers.connectors.ZoomChartController.setCollectionPeriod(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 58 Medium

psiprobe.controllers.datasources.ListAllJdbcResourceGroupsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 40 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 80 Medium

psiprobe.controllers.datasources.ListAllJdbcResourcesController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 36 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 49 Medium

psiprobe.controllers.datasources.ResetDataSourceController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.datasources.ResetDataSourceController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 88 Medium
Possible null pointer dereference in psiprobe.controllers.datasources.ResetDataSourceController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 93 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 89 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 65 High
Method psiprobe.controllers.datasources.ResetDataSourceController.setReplacePattern(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 58 Medium

psiprobe.controllers.deploy.BaseUndeployContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.deploy.BaseUndeployContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 69 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.BaseUndeployContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 62 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.BaseUndeployContextController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 70 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 70 High

psiprobe.controllers.deploy.CopySingleFileController

Bug Category Details Line Priority
Do not catch NullPointerException like in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) STYLE DCN_NULLPOINTER_EXCEPTION 77 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 154 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 98 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 113 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 121 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 156 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 164 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 173 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 178 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 181 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 184 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 188 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 79 Medium
Null passed for non-null parameter of java.nio.file.Files.delete(Path) in psiprobe.controllers.deploy.CopySingleFileController.handleFileUpload(MultipartFile, String, String, String, String, HttpServletRequest) CORRECTNESS NP_NULL_PARAM_DEREF 123 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 156 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 164 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 173 High

psiprobe.controllers.deploy.DeployConfigController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 32 High

psiprobe.controllers.deploy.DeployContextController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.deploy.DeployContextController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 54 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.DeployContextController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 50 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.DeployContextController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 55 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.DeployContextController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 59 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 55 High
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 63 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High

psiprobe.controllers.deploy.DeployController

Bug Category Details Line Priority
Do not catch NullPointerException like in psiprobe.controllers.deploy.DeployController.handleRequestInternal(HttpServletRequest, HttpServletResponse) STYLE DCN_NULLPOINTER_EXCEPTION 51 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.DeployController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 53 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 67 Medium

psiprobe.controllers.deploy.UndeployContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.deploy.UndeploySummaryContextController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.deploy.UploadWarController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 168 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 110 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 118 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 81 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 96 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 104 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 111 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 161 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 170 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 177 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 191 Medium
Possible null pointer dereference in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 195 Medium
Null passed for non-null parameter of java.nio.file.Files.delete(Path) in psiprobe.controllers.deploy.UploadWarController.handleUpload(MultipartFile, String, String, String, String, HttpServletRequest) CORRECTNESS NP_NULL_PARAM_DEREF 106 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 170 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 177 High

psiprobe.controllers.error.Error403Controller

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 99 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 108 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 110 Medium
Method psiprobe.controllers.error.Error403Controller.setAjaxExtension(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 92 Medium
Method psiprobe.controllers.error.Error403Controller.setAjaxViewName(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 73 Medium
Method psiprobe.controllers.error.Error403Controller.setViewName(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 54 Medium

psiprobe.controllers.error.Error404Controller

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 32 High

psiprobe.controllers.filters.ListAppFilterMapsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 47 Medium

psiprobe.controllers.filters.ListAppFiltersController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 38 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 47 Medium

psiprobe.controllers.help.HelpApplicationsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.help.HelpDatasourceTestController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.help.HelpDatasourcesController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.help.HelpSessionSearchController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.help.HelpThreads2Controller

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.help.HelpThreadsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.jsp.DiscardCompiledJspController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 35 High

psiprobe.controllers.jsp.DisplayJspController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 64 Medium

psiprobe.controllers.jsp.DownloadServletController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 38 High

psiprobe.controllers.jsp.RecompileJspController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 47 High

psiprobe.controllers.jsp.ViewServletSourceController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 45 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 72 Medium

psiprobe.controllers.jsp.ViewSourceController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 50 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 123 Medium

psiprobe.controllers.logs.ChangeLogLevelController

Bug Category Details Line Priority
Method psiprobe.controllers.logs.ChangeLogLevelController.handleLogFile(HttpServletRequest, HttpServletResponse, LogDestination) uses instanceof on multiple types to arbitrate logic STYLE ITC_INHERITANCE_TYPE_CHECKING 52 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 43 High

psiprobe.controllers.logs.DownloadLogController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 42 High

psiprobe.controllers.logs.FollowController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 46 Medium

psiprobe.controllers.logs.FollowedFileInfoController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 39 Medium

psiprobe.controllers.logs.ListLogsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 47 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 57 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 59 Medium

psiprobe.controllers.logs.SetupFollowController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 36 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 45 Medium

psiprobe.controllers.oshi.OshiController

Bug Category Details Line Priority
Method psiprobe.controllers.oshi.OshiController.printCpu(CentralProcessor) accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 340 Medium
Method psiprobe.controllers.oshi.OshiController.printCpu(CentralProcessor) accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 341 Medium
Method psiprobe.controllers.oshi.OshiController.initialize() calls equals on an enum instance CORRECTNESS ENMI_EQUALS_ON_ENUM 164 Medium
Method psiprobe.controllers.oshi.OshiController.printServices(OperatingSystem) calls equals on an enum instance CORRECTNESS ENMI_EQUALS_ON_ENUM 417 Medium
Method psiprobe.controllers.oshi.OshiController.printServices(OperatingSystem) calls equals on an enum instance CORRECTNESS ENMI_EQUALS_ON_ENUM 423 Medium
Possible null pointer dereference in psiprobe.controllers.oshi.OshiController.printProcesses(OperatingSystem, GlobalMemory) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 380 Medium
Possible null pointer dereference in psiprobe.controllers.oshi.OshiController.printProcesses(OperatingSystem, GlobalMemory) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 397 Medium
Class psiprobe.controllers.oshi.OshiController defines static field "psiprobe.controllers.oshi.OshiController.oshi" which appears to allow memory bloat CORRECTNESS PMB_POSSIBLE_MEMORY_BLOAT Not available Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 106 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 114 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 131 Medium

psiprobe.controllers.oshi.OshiControllerTest

Bug Category Details Line Priority
Method psiprobe.controllers.oshi.OshiControllerTest.printOperatingSystemRendersSessionsAndPermissionStatus() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 279 Medium
Method psiprobe.controllers.oshi.OshiControllerTest.getOshiData() uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 76 Medium
Method psiprobe.controllers.oshi.OshiControllerTest.invokeStatic(String, Class, Object) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 83 Medium
Method psiprobe.controllers.oshi.OshiControllerTest.invokeStatic(String, Class, Object, Class, Object) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 416 Medium
Method psiprobe.controllers.oshi.OshiControllerTest.setUp() uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 69 Medium
long[] passed to varargs method org.mockito.stubbing.OngoingStubbing.thenReturn(Object, Object[]) in psiprobe.controllers.oshi.OshiControllerTest.printCpuRendersTickLoadAndFrequencyInformation() CORRECTNESS VA_PRIMITIVE_ARRAY_PASSED_TO_OBJECT_VARARG 348 Medium

psiprobe.controllers.quickcheck.BaseTomcatAvailabilityController

Bug Category Details Line Priority
Method psiprobe.controllers.quickcheck.BaseTomcatAvailabilityController.handleRequestInternal(HttpServletRequest, HttpServletResponse) is excessively complex, with a cyclomatic complexity of 53 STYLE CC_CYCLOMATIC_COMPLEXITY 49 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 102 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 122 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 128 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 142 Medium

psiprobe.controllers.quickcheck.TomcatAvailabilityController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest

Bug Category Details Line Priority
Method psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest.handleRequestBuildsReportUsingGlobalResourcesWhenPrivateResourcesUnsupported() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 124 Medium
Method psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest.handleRequestBuildsReportUsingPrivateResources() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 72 Medium
Method psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest.handleRequestBuildsReportUsingPrivateResources() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 76 Medium
Method psiprobe.controllers.quickcheck.TomcatAvailabilityControllerTest.handleRequestBuildsReportUsingPrivateResources() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 77 Medium

psiprobe.controllers.quickcheck.TomcatAvailabilityXmlController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.servlets.ListServletMapsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 40 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 60 Medium

psiprobe.controllers.servlets.ListServletsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 67 Medium

psiprobe.controllers.servlets.ServletsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 32 High

psiprobe.controllers.sessions.ExpireSessionController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High

psiprobe.controllers.sessions.ExpireSessionsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High

psiprobe.controllers.sessions.ListSessionAttributesController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.sessions.ListSessionAttributesController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 45 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 38 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 55 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 57 Medium

psiprobe.controllers.sessions.ListSessionsController

Bug Category Details Line Priority
Class psiprobe.controllers.sessions.ListSessionsController uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 125 Medium
Possible null pointer dereference in psiprobe.controllers.sessions.ListSessionsController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 58 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 50 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 130 Medium

psiprobe.controllers.sessions.ListSessionsControllerTest

Bug Category Details Line Priority
Method psiprobe.controllers.sessions.ListSessionsControllerTest.testMatchSession() uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 157 Medium

psiprobe.controllers.sessions.RemoveSessAttributeController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High

psiprobe.controllers.sql.CachedRecordSetController

Bug Category Details Line Priority
Class psiprobe.controllers.sql.CachedRecordSetController uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 71 Medium
Possible null pointer dereference in psiprobe.controllers.sql.CachedRecordSetController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 59 Medium
Possible null pointer dereference in psiprobe.controllers.sql.CachedRecordSetController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 67 Medium
Possible null pointer dereference in psiprobe.controllers.sql.CachedRecordSetController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 79 Medium
Method psiprobe.controllers.sql.CachedRecordSetController.handleRequestInternal(HttpServletRequest, HttpServletResponse) modifies an http session attribute without calling setAttribute CORRECTNESS SCSS_SUSPICIOUS_CLUSTERED_SESSION_SUPPORT 72 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 45 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 87 Medium

psiprobe.controllers.sql.ConnectionTestController

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.sql.ConnectionTestController.addDbMetaDataEntry(Collection, String, String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 121 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ConnectionTestController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 67 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ConnectionTestController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 73 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ConnectionTestController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 97 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 99 High
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 69 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 53 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 94 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 104 Medium

psiprobe.controllers.sql.DataSourceTestController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 52 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 75 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setCollectionPeriod(long) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 100 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setCollectionPeriod(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 110 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setHistorySize(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 167 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setMaxRows(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 129 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setReplacePattern(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 186 Medium
Method psiprobe.controllers.sql.DataSourceTestController.setRowsPerPage(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 148 Medium

psiprobe.controllers.sql.ExecuteSqlController

Bug Category Details Line Priority
Class psiprobe.controllers.sql.ExecuteSqlController uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 84 Medium
Class psiprobe.controllers.sql.ExecuteSqlController uses non owned variables to synchronize on STYLE NOS_NON_OWNED_SYNCHRONIZATION 163 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 69 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 102 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 108 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 138 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 174 Medium
Method psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) does not presize the allocation of a collection PERFORMANCE PSC_PRESIZE_COLLECTIONS 148 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 175 High
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 104 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 57 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 71 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 167 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 180 Medium
This use of java/sql/Connection.prepareStatement(Ljava/lang/String;)Ljava/sql/PreparedStatement; can be vulnerable to SQL injection (with JDBC) SECURITY SQL_INJECTION_JDBC 119 Medium
Method psiprobe.controllers.sql.ExecuteSqlController.handleContext(String, Context, HttpServletRequest, HttpServletResponse) passes constant String of length 1 to character overridden method PERFORMANCE UCPM_USE_CHARACTER_PARAMETERIZED_METHOD 146 Medium

psiprobe.controllers.sql.ExecuteSqlControllerTest

Bug Category Details Line Priority
The tomcatContainer field in class psiprobe.controllers.sql.ExecuteSqlControllerTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 75 Medium
Method psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsEscapedResultSetAndStoresSessionState() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 97 Medium
Method psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsEscapedResultSetAndStoresSessionState() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 103 Medium
Method psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsEscapedResultSetAndStoresSessionState() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 106 Medium
Method psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsUpdateCountWhenStatementHasNoResultSet() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 149 Medium
Possible null pointer dereference in psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsEscapedResultSetAndStoresSessionState() due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 131 Medium
psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsEscapedResultSetAndStoresSessionState() may fail to clean up java.sql.Statement EXPERIMENTAL OBL_UNSATISFIED_OBLIGATION 96 Medium
psiprobe.controllers.sql.ExecuteSqlControllerTest.handleRequestReturnsUpdateCountWhenStatementHasNoResultSet() may fail to clean up java.sql.Statement EXPERIMENTAL OBL_UNSATISFIED_OBLIGATION 148 Medium

psiprobe.controllers.sql.QueryHistoryController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 37 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 56 Medium

psiprobe.controllers.sql.QueryHistoryItemController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 68 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 43 High
This use of java/io/PrintWriter.print(Ljava/lang/String;)V could be vulnerable to XSS in the Servlet SECURITY XSS_SERVLET 65 Medium

psiprobe.controllers.sql.QueryHistoryItemControllerTest

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.controllers.sql.QueryHistoryItemControllerTest.handleRequestIgnoresMissingSessionDataAndOutOfBoundsHistoryIndex() due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 54 Medium
Possible null pointer dereference in psiprobe.controllers.sql.QueryHistoryItemControllerTest.handleRequestWritesRequestedSqlHistoryItem() due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 35 Medium

psiprobe.controllers.system.AdviseGarbageCollectionController

Bug Category Details Line Priority
psiprobe.controllers.system.AdviseGarbageCollectionController.handleRequestInternal(HttpServletRequest, HttpServletResponse) forces garbage collection; extremely dubious except in benchmarking code PERFORMANCE DM_GC 82 High
Method psiprobe.controllers.system.AdviseGarbageCollectionController.handleRequestInternal(HttpServletRequest, HttpServletResponse) triggers finalization when calling Runtime.runFinalization() CORRECTNESS MDM_RUNFINALIZATION 79 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 62 High
Method psiprobe.controllers.system.AdviseGarbageCollectionController.setReplacePattern(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 55 Medium

psiprobe.controllers.system.BaseMemoryStatsController

Bug Category Details Line Priority
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 56 Medium

psiprobe.controllers.system.BaseSysInfoController

Bug Category Details Line Priority
psiprobe.controllers.system.BaseSysInfoController.getFilterOutKeys() may expose internal representation by returning BaseSysInfoController.filterOutKeys MALICIOUS_CODE EI_EXPOSE_REP 50 Medium
psiprobe.controllers.system.BaseSysInfoController.setFilterOutKeys(List) may expose internal representation by storing an externally mutable object into BaseSysInfoController.filterOutKeys MALICIOUS_CODE EI_EXPOSE_REP2 59 Medium
Possible null pointer dereference in psiprobe.controllers.system.BaseSysInfoController.handleRequestInternal(HttpServletRequest, HttpServletResponse) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 95 Medium
Method psiprobe.controllers.system.BaseSysInfoController.handleRequestInternal(HttpServletRequest, HttpServletResponse) does not presize the allocation of a collection PERFORMANCE PSC_PRESIZE_COLLECTIONS 92 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 103 Medium

psiprobe.controllers.system.MemoryStatsAjaxController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.system.MemoryStatsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 43 High

psiprobe.controllers.system.OsInfoAjaxController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.system.OsInfoController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 33 High

psiprobe.controllers.system.SysInfoController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 31 High

psiprobe.controllers.system.SysPropsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High

psiprobe.controllers.threads.GetClassLoaderUrlsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 43 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 66 Medium

psiprobe.controllers.threads.ImplSelectorController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 79 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 87 Medium
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 89 Medium
Method psiprobe.controllers.threads.ImplSelectorController.setImpl1Controller(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 53 Medium
Method psiprobe.controllers.threads.ImplSelectorController.setImpl2Controller(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 72 Medium

psiprobe.controllers.threads.KillThreadController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 58 High
Method psiprobe.controllers.threads.KillThreadController.setReplacePattern(String) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 51 Medium

psiprobe.controllers.threads.ListSunThreadsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 45 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 99 Medium

psiprobe.controllers.threads.ListThreadPoolsController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 42 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 50 Medium

psiprobe.controllers.threads.ListThreadsController

Bug Category Details Line Priority
Method psiprobe.controllers.threads.ListThreadsController.enumerateThreads(Map) does not presize the allocation of a collection PERFORMANCE PSC_PRESIZE_COLLECTIONS 106 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 41 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 60 Medium

psiprobe.controllers.threads.ThreadStackController

Bug Category Details Line Priority
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 68 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 120 Medium
Method psiprobe.controllers.threads.ThreadStackController.setStackElementCount(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 61 Medium

psiprobe.controllers.truststore.TrustStoreController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 75 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 54 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 94 Medium

psiprobe.controllers.wrapper.RestartJvmController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 54 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 56 Medium

psiprobe.controllers.wrapper.StopJvmController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 75 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 60 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 77 Medium
Method psiprobe.controllers.wrapper.StopJvmController.setStopExitCode(int) of Singleton class writes to a field in an unsynchronized manner CORRECTNESS USFW_UNSYNCHRONIZED_SINGLETON_FIELD_WRITES 53 Medium

psiprobe.controllers.wrapper.ThreadDumpController

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 54 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 39 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 56 Medium

psiprobe.controllers.wrapper.WrapperInfoController

Bug Category Details Line Priority
Method psiprobe.controllers.wrapper.WrapperInfoController.handleRequestInternal(HttpServletRequest, HttpServletResponse) appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 54 Medium
Method psiprobe.controllers.wrapper.WrapperInfoController.handleRequestInternal(HttpServletRequest, HttpServletResponse) appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 56 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 66 Medium
Unrestricted Spring's RequestMapping makes the method vulnerable to CSRF attacks SECURITY SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING 40 High
ModelAndView populated with user controlled parameters SECURITY SPRING_FILE_DISCLOSURE 69 Medium

psiprobe.jfreechart.XYLine3DRenderer

Bug Category Details Line Priority
Class psiprobe.jfreechart.XYLine3DRenderer defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium
Method psiprobe.jfreechart.XYLine3DRenderer.hashCode() stores return result in local before immediately returning it STYLE USBR_UNNECESSARY_STORE_BEFORE_RETURN 272 Medium

psiprobe.jfreechart.XYLine3DRendererTest

Bug Category Details Line Priority
Object deserialization is used in psiprobe.jfreechart.XYLine3DRendererTest.testSerialization() SECURITY OBJECT_DESERIALIZATION 104 High
Object deserialization is used in psiprobe.jfreechart.XYLine3DRendererTest.testSerializationWithNullWallPaint() SECURITY OBJECT_DESERIALIZATION 245 High
Method psiprobe.jfreechart.XYLine3DRendererTest.testHashCodeConsistency() appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 149 Medium
Method psiprobe.jfreechart.XYLine3DRendererTest.testIsLinePass() uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 283 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testDefaultConstructorFields() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 257 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testDefaultConstructorFields() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 258 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testDefaultValues() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 44 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testDefaultValues() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 45 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSetNegativeOffsets() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 190 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSetNegativeOffsets() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 191 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSettersAndGetters() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 61 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSettersAndGetters() asserts that two doubles are exactly equal STYLE UTAO_JUNIT_ASSERTION_ODDITIES_INEXACT_DOUBLE 62 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSerializationWithNullWallPaint() passes null to Assert.assertEquals CORRECTNESS UTAO_JUNIT_ASSERTION_ODDITIES_USE_ASSERT_NULL 248 Medium
JUnit test method psiprobe.jfreechart.XYLine3DRendererTest.testSetWallPaintNull() passes null to Assert.assertEquals CORRECTNESS UTAO_JUNIT_ASSERTION_ODDITIES_USE_ASSERT_NULL 179 Medium

psiprobe.jsp.AddQueryParamTagTest

Bug Category Details Line Priority
The pageContext field in class psiprobe.jsp.AddQueryParamTagTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 48 Medium

psiprobe.jsp.OutTagTest

Bug Category Details Line Priority
The pageContext field in class psiprobe.jsp.OutTagTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 47 Medium

psiprobe.jsp.ParamToggleTagTest

Bug Category Details Line Priority
The pageContext field in class psiprobe.jsp.ParamToggleTagTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 48 Medium

psiprobe.jsp.VisualScoreTag

Bug Category Details Line Priority
Class psiprobe.jsp.VisualScoreTag defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium
Tag library psiprobe.jsp.VisualScoreTag is not recycleable CORRECTNESS NRTL_NON_RECYCLEABLE_TAG_LIB 109 Medium
Tag library psiprobe.jsp.VisualScoreTag is not recycleable CORRECTNESS NRTL_NON_RECYCLEABLE_TAG_LIB 115 Medium

psiprobe.jsp.VisualScoreTagTest

Bug Category Details Line Priority
Method psiprobe.jsp.VisualScoreTagTest.callCalculateSuffix(int, int, int, int) excessively uses methods of another class STYLE CE_CLASS_ENVY 240-256 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixBlueBorder() excessively uses methods of another class STYLE CE_CLASS_ENVY 127-139 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixFullRedBorder() excessively uses methods of another class STYLE CE_CLASS_ENVY 111-123 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixShowAFalse() excessively uses methods of another class STYLE CE_CLASS_ENVY 59-72 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixShowBFalse() excessively uses methods of another class STYLE CE_CLASS_ENVY 76-90 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixShowEmptyBlocksFalse() excessively uses methods of another class STYLE CE_CLASS_ENVY 94-107 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixValueBelowMin() excessively uses methods of another class STYLE CE_CLASS_ENVY 158-171 Medium
Method psiprobe.jsp.VisualScoreTagTest.testCalculateSuffixWithValue2BelowZero() excessively uses methods of another class STYLE CE_CLASS_ENVY 143-154 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 219 High

psiprobe.jsp.VolumeTagTest

Bug Category Details Line Priority
The pageContext field in class psiprobe.jsp.VolumeTagTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 47 Medium

psiprobe.model.ApplicationResource

Bug Category Details Line Priority
psiprobe.model.ApplicationResource.getDataSourceInfo() may expose internal representation by returning ApplicationResource.dataSourceInfo MALICIOUS_CODE EI_EXPOSE_REP 159 Medium
psiprobe.model.ApplicationResource.setDataSourceInfo(DataSourceInfo) may expose internal representation by storing an externally mutable object into ApplicationResource.dataSourceInfo MALICIOUS_CODE EI_EXPOSE_REP2 168 Medium

psiprobe.model.ApplicationSession

Bug Category Details Line Priority
psiprobe.model.ApplicationSession.getAttributes() may expose internal representation by returning ApplicationSession.attributes MALICIOUS_CODE EI_EXPOSE_REP 206 Medium
psiprobe.model.ApplicationSession.setAttributes(List) may expose internal representation by storing an externally mutable object into ApplicationSession.attributes MALICIOUS_CODE EI_EXPOSE_REP2 215 Medium

psiprobe.model.Connector

Bug Category Details Line Priority
psiprobe.model.Connector.getRequestProcessors() may expose internal representation by returning Connector.requestProcessors MALICIOUS_CODE EI_EXPOSE_REP 195 Medium
psiprobe.model.Connector.setRequestProcessors(List) may expose internal representation by storing an externally mutable object into Connector.requestProcessors MALICIOUS_CODE EI_EXPOSE_REP2 204 Medium

psiprobe.model.DataSourceInfoGroupTest

Bug Category Details Line Priority
Method psiprobe.model.DataSourceInfoGroupTest.testAddDataSourceInfo() excessively uses methods of another class STYLE CE_CLASS_ENVY 73-90 Medium
Method psiprobe.model.DataSourceInfoGroupTest.testAddMethods() excessively uses methods of another class STYLE CE_CLASS_ENVY 59-69 Medium

psiprobe.model.DisconnectedLogDestination

Bug Category Details Line Priority
psiprobe.model.DisconnectedLogDestination.getApplication() may expose internal representation by returning DisconnectedLogDestination.application MALICIOUS_CODE EI_EXPOSE_REP 98 Medium

psiprobe.model.DisconnectedLogDestinationTest

Bug Category Details Line Priority
Method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() excessively uses methods of another class STYLE CE_CLASS_ENVY 44-78 Medium
Method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 47 Medium
Method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 48 Medium
Method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 65 Medium
Method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 66 Medium
JUnit test method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 65 Medium
JUnit test method psiprobe.model.DisconnectedLogDestinationTest.testBuilderFromDestination() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 66 Medium

psiprobe.model.SessionSearchInfo

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 326 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 378 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 426 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 462 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 498 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 534 Medium

psiprobe.model.SessionSearchInfoTest

Bug Category Details Line Priority
Method psiprobe.model.SessionSearchInfoTest.emptyAndValidBranchCoverageTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 153-212 Medium
Method psiprobe.model.SessionSearchInfoTest.numericAndDefensiveListBehaviorTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 107-146 Medium
Method psiprobe.model.SessionSearchInfoTest.patternValidationTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 77-100 Medium
Method psiprobe.model.SessionSearchInfoTest.sessionSearchDefaultsAndFlagsTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 38-70 Medium

psiprobe.model.SunThread

Bug Category Details Line Priority
psiprobe.model.SunThread.getExecutionPoint() may expose internal representation by returning SunThread.executionPoint MALICIOUS_CODE EI_EXPOSE_REP 237 Medium
psiprobe.model.SunThread.setExecutionPoint(ThreadStackElement) may expose internal representation by storing an externally mutable object into SunThread.executionPoint MALICIOUS_CODE EI_EXPOSE_REP2 246 Medium

psiprobe.model.SystemInformation

Bug Category Details Line Priority
psiprobe.model.SystemInformation.getSystemProperties() may expose internal representation by returning SystemInformation.systemProperties MALICIOUS_CODE EI_EXPOSE_REP 143 Medium
psiprobe.model.SystemInformation.setSystemProperties(Map) may expose internal representation by storing an externally mutable object into SystemInformation.systemProperties MALICIOUS_CODE EI_EXPOSE_REP2 152 Medium

psiprobe.model.SystemInformationTest

Bug Category Details Line Priority
JUnit test method psiprobe.model.SystemInformationTest.testSystemPropertySet() passes boolean expression to Assert.assertFalse / Assert.assertTrue CORRECTNESS UTAO_JUNIT_ASSERTION_ODDITIES_USE_ASSERT_EQUALS 76 Medium

psiprobe.model.certificates.Cert

Bug Category Details Line Priority
Class psiprobe.model.certificates.Cert defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium

psiprobe.model.certificates.CertificateInfo

Bug Category Details Line Priority
Class psiprobe.model.certificates.CertificateInfo defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium

psiprobe.model.certificates.ConnectorInfo

Bug Category Details Line Priority
Class psiprobe.model.certificates.ConnectorInfo defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium

psiprobe.model.certificates.SslHostConfigInfo

Bug Category Details Line Priority
Class psiprobe.model.certificates.SslHostConfigInfo defines a computed serialVersionUID that doesn't equate to the calculated value CORRECTNESS IMC_IMMATURE_CLASS_BAD_SERIALVERSIONUID Not available Medium

psiprobe.model.jmx.ThreadPoolObjectName

Bug Category Details Line Priority
psiprobe.model.jmx.ThreadPoolObjectName.getGlobalRequestProcessorName() may expose internal representation by returning ThreadPoolObjectName.globalRequestProcessorName MALICIOUS_CODE EI_EXPOSE_REP 49 Medium
psiprobe.model.jmx.ThreadPoolObjectName.getThreadPoolName() may expose internal representation by returning ThreadPoolObjectName.threadPoolName MALICIOUS_CODE EI_EXPOSE_REP 40 Medium
psiprobe.model.jmx.ThreadPoolObjectName.setGlobalRequestProcessorName(ObjectName) may expose internal representation by storing an externally mutable object into ThreadPoolObjectName.globalRequestProcessorName MALICIOUS_CODE EI_EXPOSE_REP2 76 Medium
psiprobe.model.jmx.ThreadPoolObjectName.setThreadPoolName(ObjectName) may expose internal representation by storing an externally mutable object into ThreadPoolObjectName.threadPoolName MALICIOUS_CODE EI_EXPOSE_REP2 67 Medium

psiprobe.model.jsp.Item

Bug Category Details Line Priority
psiprobe.model.jsp.Item.getException() may expose internal representation by returning Item.exception MALICIOUS_CODE EI_EXPOSE_REP 88 Medium
psiprobe.model.jsp.Item.setException(Exception) may expose internal representation by storing an externally mutable object into Item.exception MALICIOUS_CODE EI_EXPOSE_REP2 97 Medium

psiprobe.model.sql.DataSourceTestInfo

Bug Category Details Line Priority
psiprobe.model.sql.DataSourceTestInfo.getQueryHistory() may expose internal representation by returning DataSourceTestInfo.queryHistory MALICIOUS_CODE EI_EXPOSE_REP 89 Medium
psiprobe.model.sql.DataSourceTestInfo.getResults() may expose internal representation by returning DataSourceTestInfo.results MALICIOUS_CODE EI_EXPOSE_REP 71 Medium
psiprobe.model.sql.DataSourceTestInfo.setResults(List) may expose internal representation by storing an externally mutable object into DataSourceTestInfo.results MALICIOUS_CODE EI_EXPOSE_REP2 80 Medium

psiprobe.model.sql.DataSourceTestInfoTest

Bug Category Details Line Priority
Method psiprobe.model.sql.DataSourceTestInfoTest.testAddQueryToHistory() excessively uses methods of another class STYLE CE_CLASS_ENVY 39-67 Medium

psiprobe.model.stats.StatsCollection

Bug Category Details Line Priority
Shared primitive variable "maxFiles" in one thread may not yield the value of the most recent write from another thread MT_CORRECTNESS AT_STALE_THREAD_WRITE_OF_PRIMITIVE 138 Medium
Possible null pointer dereference in psiprobe.model.stats.StatsCollection.setApplicationContext(ApplicationContext) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 378 Medium
Method psiprobe.model.stats.StatsCollection.shiftFiles(int) appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 236 Medium

psiprobe.model.wrapper.WrapperInfo

Bug Category Details Line Priority
psiprobe.model.wrapper.WrapperInfo.getProperties() may expose internal representation by returning WrapperInfo.properties MALICIOUS_CODE EI_EXPOSE_REP 165 Medium
psiprobe.model.wrapper.WrapperInfo.setProperties(Set) may expose internal representation by storing an externally mutable object into WrapperInfo.properties MALICIOUS_CODE EI_EXPOSE_REP2 174 Medium

psiprobe.tokenizer.StringTokenizer

Bug Category Details Line Priority
Constructor new psiprobe.tokenizer.StringTokenizer(String) makes call to non-final method CORRECTNESS PCOA_PARTIALLY_CONSTRUCTED_OBJECT_ACCESS 40 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 57 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 67 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 77 Medium

psiprobe.tokenizer.Tokenizer

Bug Category Details Line Priority
Constructor new psiprobe.tokenizer.Tokenizer(Reader, int) makes call to non-final method CORRECTNESS PCOA_PARTIALLY_CONSTRUCTED_OBJECT_ACCESS 95 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 406 Medium

psiprobe.tools.ApplicationUtils

Bug Category Details Line Priority
Method psiprobe.tools.ApplicationUtils.getApplication(Context, ResourceResolver, boolean, ContainerWrapperBean) accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 146 Medium
Method psiprobe.tools.ApplicationUtils.getApplicationDataSourceUsageScores(Context, ResourceResolver, ContainerWrapperBean) accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 247 Medium
Unconstrained method psiprobe.tools.ApplicationUtils.getApplicationDataSourceUsageScores(Context, ResourceResolver, ContainerWrapperBean) converts checked exception to unchecked STYLE EXS_EXCEPTION_SOFTENING_NO_CONSTRAINTS 242 High
Method psiprobe.tools.ApplicationUtils.collectApplicationServletStats(Context, Application) uses instanceof on multiple types to arbitrate logic STYLE ITC_INHERITANCE_TYPE_CHECKING 204 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 322 Medium

psiprobe.tools.ApplicationUtilsTest

Bug Category Details Line Priority
Method psiprobe.tools.ApplicationUtilsTest.collectApplicationServletStatsAggregatesStandardWrappers() excessively uses methods of another class STYLE CE_CLASS_ENVY 116-144 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationDataSourceUsageScoresUsesMaximumAcrossResources() accesses list or array with constant index CORRECTNESS CLI_CONSTANT_LIST_INDEX 175 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationServletAndServletsBuildServletInfoFromWrappers() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 225 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationServletMapsSkipsNullMappingsAndAddsWrapperMetadata() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 250 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationSessionCollectsAttributesAndMetadata() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 66 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationSessionHandlesInvalidatedHttpSessionGracefully() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 97 Medium
Method psiprobe.tools.ApplicationUtilsTest.getApplicationSessionReturnsNullForInvalidSession() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 55 Medium

psiprobe.tools.AsyncSocketFactory

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 70 Medium

psiprobe.tools.AsyncSocketFactory$SocketRunnable

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 206 Medium
Unencrypted socket to psiprobe.tools.AsyncSocketFactory$SocketRunnable (instead of SSLSocket) SECURITY UNENCRYPTED_SOCKET 199 Medium

psiprobe.tools.AsyncSocketFactory$TimeoutRunnable

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 254 Medium

psiprobe.tools.BackwardsFileStream

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.BackwardsFileStream at new psiprobe.tools.BackwardsFileStream(File) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 38 Medium

psiprobe.tools.InstrumentsTests$1Child

Bug Category Details Line Priority
Unread field: psiprobe.tools.InstrumentsTests$1Child.childField PERFORMANCE URF_UNREAD_FIELD 168 Medium

psiprobe.tools.InstrumentsTests$1Container

Bug Category Details Line Priority
Unread field: psiprobe.tools.InstrumentsTests$1Container.value PERFORMANCE URF_UNREAD_FIELD 147 Medium

psiprobe.tools.InstrumentsTests$1Parent

Bug Category Details Line Priority
Unread field: psiprobe.tools.InstrumentsTests$1Parent.parentField PERFORMANCE URF_UNREAD_FIELD 165 Medium

psiprobe.tools.InstrumentsTests$1SimpleData

Bug Category Details Line Priority
Unread field: psiprobe.tools.InstrumentsTests$1SimpleData.x PERFORMANCE URF_UNREAD_FIELD 199 Medium
Unread field: psiprobe.tools.InstrumentsTests$1SimpleData.y PERFORMANCE URF_UNREAD_FIELD 200 Medium

psiprobe.tools.JmxTools

Bug Category Details Line Priority
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 58 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 61 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 64 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 67 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 89 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 92 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 245 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 248 Medium

psiprobe.tools.JmxToolsTest

Bug Category Details Line Priority
Method psiprobe.tools.JmxToolsTest.testGetBooleanAttr_MBeanServer() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 127 Medium

psiprobe.tools.LogOutputStream

Bug Category Details Line Priority
Constructor new psiprobe.tools.LogOutputStream(Logger, int) declares a Logger parameter CORRECTNESS LO_SUSPECT_LOG_PARAMETER 66-72 Medium
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 169 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 172 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 175 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 178 High
Format should be constant. Use placeholder to reduce the needless cost of parameter construction. see http://www.slf4j.org/faq.html#logging_performance CORRECTNESS SLF4J_FORMAT_SHOULD_BE_CONST 181 High
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 87 Medium

psiprobe.tools.LogOutputStreamTest

Bug Category Details Line Priority
Method psiprobe.tools.LogOutputStreamTest.testFlushWithEmptyBuffer() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 104 Medium
Method psiprobe.tools.LogOutputStreamTest.testLevelDebug() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 60 Medium
Method psiprobe.tools.LogOutputStreamTest.testLevelInfo() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 69 Medium
Method psiprobe.tools.LogOutputStreamTest.testLevelTrace() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 51 Medium
Method psiprobe.tools.LogOutputStreamTest.testLevelWarn() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 78 Medium
Logger should be final field. Change this field (log) to final field. STYLE SLF4J_LOGGER_SHOULD_BE_FINAL Not available Medium
To prevent illegal usage, logger should be private field. Change this field (log) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium

psiprobe.tools.MailMessage

Bug Category Details Line Priority
Constructor new psiprobe.tools.MailMessage(String, String, String) makes call to non-final method CORRECTNESS PCOA_PARTIALLY_CONSTRUCTED_OBJECT_ACCESS 54 Medium

psiprobe.tools.ObjectWrapperTest

Bug Category Details Line Priority
JUnit test method psiprobe.tools.ObjectWrapperTest.testEqualsDifferentClass() passes boolean expression to Assert.assertFalse / Assert.assertTrue CORRECTNESS UTAO_JUNIT_ASSERTION_ODDITIES_USE_ASSERT_NOT_EQUALS 60 Medium

psiprobe.tools.SecurityUtils

Bug Category Details Line Priority
Possible null pointer dereference in psiprobe.tools.SecurityUtils.userHasRole(String) due to return value of called method STYLE NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE 59 Medium

psiprobe.tools.SimpleAccessor

Bug Category Details Line Priority
Method psiprobe.tools.SimpleAccessor.post(Field, boolean) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 86 Medium
Method psiprobe.tools.SimpleAccessor.pre(Object, Field) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 69 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 32 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 71 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 88 Medium

psiprobe.tools.SimpleAccessorTest$Target

Bug Category Details Line Priority
The privateField field in class psiprobe.tools.SimpleAccessorTest$Target is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 27 Medium
Instance field psiprobe.tools.SimpleAccessorTest$Target.privateField likely could be defined as static CORRECTNESS SPP_FIELD_COULD_BE_STATIC Not available Medium

psiprobe.tools.SizeExpressionTests

Bug Category Details Line Priority
Method psiprobe.tools.SizeExpressionTests.formatNoDecimalBase10Test() excessively uses methods of another class STYLE CE_CLASS_ENVY 65-73 Medium
Method psiprobe.tools.SizeExpressionTests.formatNoDecimalBase2Test() excessively uses methods of another class STYLE CE_CLASS_ENVY 50-58 Medium
Method psiprobe.tools.SizeExpressionTests.formatOneDecimalBase10Test() excessively uses methods of another class STYLE CE_CLASS_ENVY 95-103 Medium
Method psiprobe.tools.SizeExpressionTests.formatOneDecimalBase2Test() excessively uses methods of another class STYLE CE_CLASS_ENVY 80-88 Medium
Method psiprobe.tools.SizeExpressionTests.parseWithUnitTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 136-148 Medium
Method psiprobe.tools.SizeExpressionTests.parseWithoutUnitTest() excessively uses methods of another class STYLE CE_CLASS_ENVY 155-167 Medium
Method psiprobe.tools.SizeExpressionTests.setUp() calls Locale.setDefault(), changing locale for all threads MT_CORRECTNESS MDM_SETDEFAULTLOCALE 34 Medium
Method psiprobe.tools.SizeExpressionTests.tearDown() calls Locale.setDefault(), changing locale for all threads MT_CORRECTNESS MDM_SETDEFAULTLOCALE 42 Medium

psiprobe.tools.Whois$Response

Bug Category Details Line Priority
psiprobe.tools.Whois$Response.getData() may expose internal representation by returning Whois$Response.data MALICIOUS_CODE EI_EXPOSE_REP 177 Medium

psiprobe.tools.logging.DefaultAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.DefaultAccessor.getApplication() may expose internal representation by returning DefaultAccessor.application MALICIOUS_CODE EI_EXPOSE_REP 43 Medium
psiprobe.tools.logging.DefaultAccessor.setApplication(Application) may expose internal representation by storing an externally mutable object into DefaultAccessor.application MALICIOUS_CODE EI_EXPOSE_REP2 52 Medium
Class psiprobe.tools.logging.DefaultAccessor defines a non private logger using a static class context CORRECTNESS LO_NON_PRIVATE_STATIC_LOGGER 29 Medium
To prevent illegal usage, logger should be private field. Change this field (logger) to private field. STYLE SLF4J_LOGGER_SHOULD_BE_PRIVATE Not available Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 101 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 137 Medium

psiprobe.tools.logging.commons.AbstractLoggerAccessorVisitor

Bug Category Details Line Priority
Method psiprobe.tools.logging.commons.AbstractLoggerAccessorVisitor.visit() orders expressions in a conditional in a sub optimal way PERFORMANCE SEO_SUBOPTIMAL_EXPRESSION_ORDER 44 Medium

psiprobe.tools.logging.commons.CommonsLoggerAccessorTest$LoggerHolder

Bug Category Details Line Priority
The logger field in class psiprobe.tools.logging.commons.CommonsLoggerAccessorTest$LoggerHolder is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 92 Medium

psiprobe.tools.logging.commons.GetAllDestinationsVisitor

Bug Category Details Line Priority
psiprobe.tools.logging.commons.GetAllDestinationsVisitor.getDestinations() may expose internal representation by returning GetAllDestinationsVisitor.destinations MALICIOUS_CODE EI_EXPOSE_REP 34 Medium

psiprobe.tools.logging.jdk.Jdk14HandlerAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.jdk.Jdk14HandlerAccessor.getLoggerAccessor() may expose internal representation by returning Jdk14HandlerAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 34 Medium
psiprobe.tools.logging.jdk.Jdk14HandlerAccessor.setLoggerAccessor(Jdk14LoggerAccessor) may expose internal representation by storing an externally mutable object into Jdk14HandlerAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 43 Medium

psiprobe.tools.logging.jdk.Jdk14LoggerAccessor

Bug Category Details Line Priority
Class psiprobe.tools.logging.jdk.Jdk14LoggerAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 27-220 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 112 Medium

psiprobe.tools.logging.jdk.Jdk14LoggerAccessorTest

Bug Category Details Line Priority
The mockLogger field in class psiprobe.tools.logging.jdk.Jdk14LoggerAccessorTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 38 Medium

psiprobe.tools.logging.jdk.Jdk14ManagerAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.jdk.Jdk14ManagerAccessor at new psiprobe.tools.logging.jdk.Jdk14ManagerAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 42 Medium

psiprobe.tools.logging.jdk.JuliHandlerAccessorTest

Bug Category Details Line Priority
Method psiprobe.tools.logging.jdk.JuliHandlerAccessorTest.testGetFile_MissingField_ReturnsStdoutFile() appears to call the same method on the same object redundantly PERFORMANCE PRMC_POSSIBLY_REDUNDANT_METHOD_CALLS 84 Medium

psiprobe.tools.logging.log4j.Log4JAppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.log4j.Log4JAppenderAccessor.getLoggerAccessor() may expose internal representation by returning Log4JAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 32 Medium
psiprobe.tools.logging.log4j.Log4JAppenderAccessor.setLoggerAccessor(Log4JLoggerAccessor) may expose internal representation by storing an externally mutable object into Log4JAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 41 Medium

psiprobe.tools.logging.log4j.Log4JLoggerAccessor

Bug Category Details Line Priority
Class psiprobe.tools.logging.log4j.Log4JLoggerAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 25-155 Medium

psiprobe.tools.logging.log4j.Log4JManagerAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.log4j.Log4JManagerAccessor at new psiprobe.tools.logging.log4j.Log4JManagerAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 36 Medium
Method psiprobe.tools.logging.log4j.Log4JManagerAccessor.getAppenders() allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 112 Medium

psiprobe.tools.logging.log4j2.Log4J2AppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.log4j2.Log4J2AppenderAccessor.getLoggerAccessor() may expose internal representation by returning Log4J2AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 34 Medium
psiprobe.tools.logging.log4j2.Log4J2AppenderAccessor.setLoggerAccessor(Log4J2LoggerConfigAccessor) may expose internal representation by storing an externally mutable object into Log4J2AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 43 Medium
This API (java/io/File.<init>(Ljava/lang/String;)V) reads a file whose location might be specified by user input SECURITY PATH_TRAVERSAL_IN 112 Medium

psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessor.setLoggerContext(Log4J2LoggerContextAccessor) may expose internal representation by storing an externally mutable object into Log4J2LoggerConfigAccessor.loggerContext MALICIOUS_CODE EI_EXPOSE_REP2 135 Medium
Class psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 27-242 Medium

psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessorTest

Bug Category Details Line Priority
The mockLoggerContext field in class psiprobe.tools.logging.log4j2.Log4J2LoggerConfigAccessorTest is used only as a local, but defined on class level CORRECTNESS FCBL_FIELD_COULD_BE_LOCAL 49 Medium

psiprobe.tools.logging.log4j2.Log4J2WebLoggerContextUtilsAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.log4j2.Log4J2WebLoggerContextUtilsAccessor at new psiprobe.tools.logging.log4j2.Log4J2WebLoggerContextUtilsAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 41 Medium

psiprobe.tools.logging.logback.LogbackAppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.logback.LogbackAppenderAccessor.getLoggerAccessor() may expose internal representation by returning LogbackAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 36 Medium
psiprobe.tools.logging.logback.LogbackAppenderAccessor.setLoggerAccessor(LogbackLoggerAccessor) may expose internal representation by storing an externally mutable object into LogbackAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 45 Medium

psiprobe.tools.logging.logback.LogbackAppenderAccessorTest

Bug Category Details Line Priority
Method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 54 Medium
Method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 56 Medium
Method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 61 Medium
Method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 63 Medium
JUnit test method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsContext() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 56 Medium
JUnit test method psiprobe.tools.logging.logback.LogbackAppenderAccessorTest.testIsRoot() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 63 Medium

psiprobe.tools.logging.logback.LogbackFactoryAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.logback.LogbackFactoryAccessor at new psiprobe.tools.logging.logback.LogbackFactoryAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 48 Medium
Method psiprobe.tools.logging.logback.LogbackFactoryAccessor.getAppenders() allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 115 Medium

psiprobe.tools.logging.logback.LogbackLoggerAccessor

Bug Category Details Line Priority
Class psiprobe.tools.logging.logback.LogbackLoggerAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 28-194 Medium

psiprobe.tools.logging.logback13.Logback13AppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.logback13.Logback13AppenderAccessor.getLoggerAccessor() may expose internal representation by returning Logback13AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 36 Medium
psiprobe.tools.logging.logback13.Logback13AppenderAccessor.setLoggerAccessor(Logback13LoggerAccessor) may expose internal representation by storing an externally mutable object into Logback13AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 45 Medium

psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest

Bug Category Details Line Priority
Method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 54 Medium
Method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 56 Medium
Method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 61 Medium
Method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 63 Medium
JUnit test method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsContext() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 56 Medium
JUnit test method psiprobe.tools.logging.logback13.Logback13AppenderAccessorTest.testIsRoot() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 63 Medium

psiprobe.tools.logging.logback13.Logback13FactoryAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.logback13.Logback13FactoryAccessor at new psiprobe.tools.logging.logback13.Logback13FactoryAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 52 Medium
Method new psiprobe.tools.logging.logback13.Logback13FactoryAccessor(ClassLoader) declares RuntimeException in throws clause STYLE DRE_DECLARED_RUNTIME_EXCEPTION 49-75 Medium
Method psiprobe.tools.logging.logback13.Logback13FactoryAccessor.getAppenders() allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 129 Medium
Method psiprobe.tools.logging.logback13.Logback13FactoryAccessor.findServiceProviders(ClassLoader) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 161 Medium
Method psiprobe.tools.logging.logback13.Logback13FactoryAccessor.findServiceProviders(ClassLoader) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 163 Medium

psiprobe.tools.logging.logback13.Logback13LoggerAccessor

Bug Category Details Line Priority
Class psiprobe.tools.logging.logback13.Logback13LoggerAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 28-192 Medium

psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessor.getLoggerAccessor() may expose internal representation by returning TomcatSlf4jLogbackAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 36 Medium
psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessor.setLoggerAccessor(TomcatSlf4jLogbackLoggerAccessor) may expose internal representation by storing an externally mutable object into TomcatSlf4jLogbackAppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 45 Medium
Class psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 25-133 Medium

psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest

Bug Category Details Line Priority
Method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 54 Medium
Method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 56 Medium
Method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 61 Medium
Method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 63 Medium
JUnit test method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsContext() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 56 Medium
JUnit test method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackAppenderAccessorTest.testIsRoot() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 63 Medium

psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackFactoryAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackFactoryAccessor at new psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackFactoryAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 49 Medium
Method psiprobe.tools.logging.slf4jlogback.TomcatSlf4jLogbackFactoryAccessor.getAppenders() allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 120 Medium

psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessor

Bug Category Details Line Priority
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessor.getLoggerAccessor() may expose internal representation by returning TomcatSlf4jLogback13AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP 36 Medium
psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessor.setLoggerAccessor(TomcatSlf4jLogback13LoggerAccessor) may expose internal representation by storing an externally mutable object into TomcatSlf4jLogback13AppenderAccessor.loggerAccessor MALICIOUS_CODE EI_EXPOSE_REP2 45 Medium

psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest

Bug Category Details Line Priority
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 54 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsContext() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 56 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 61 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsRoot() needlessly boxes a boolean constant PERFORMANCE NAB_NEEDLESS_BOOLEAN_CONSTANT_CONVERSION 63 Medium
JUnit test method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsContext() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 56 Medium
JUnit test method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13AppenderAccessorTest.testIsRoot() asserts that a value is equal to true or false STYLE UTAO_JUNIT_ASSERTION_ODDITIES_BOOLEAN_ASSERT 63 Medium

psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor at new psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor(ClassLoader) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 53 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor.getAppenders() allocates an object that is used in a constant way in a loop PERFORMANCE PCAIL_POSSIBLE_CONSTANT_ALLOCATION_IN_LOOP 134 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor.findServiceProviders(ClassLoader) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 166 Medium
Method psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13FactoryAccessor.findServiceProviders(ClassLoader) uses AccessibleObject.setAccessible to modify accessibility of classes CORRECTNESS RFI_SET_ACCESSIBLE 168 Medium

psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13LoggerAccessor

Bug Category Details Line Priority
Class psiprobe.tools.logging.slf4jlogback13.TomcatSlf4jLogback13LoggerAccessor has a circular dependency with other classes CORRECTNESS FCCD_FIND_CLASS_CIRCULAR_DEPENDENCY 28-201 Medium

psiprobe.tools.url.UrlParser

Bug Category Details Line Priority
Exception thrown in class psiprobe.tools.url.UrlParser at new psiprobe.tools.url.UrlParser(String) will leave the constructor. The object under construction remains partially initialized and may be vulnerable to Finalizer attacks. BAD_PRACTICE CT_CONSTRUCTOR_THROW 47 Medium
Method new psiprobe.tools.url.UrlParser(String) throws alternative exception from catch block without history CORRECTNESS LEST_LOST_EXCEPTION_STACK_TRACE 75 Medium
To make log readable, log format () should contain non-sign character. BAD_PRACTICE SLF4J_SIGN_ONLY_FORMAT 74 Medium