From Application Security and Development Security Technical Implementation Guide
Part of ASDV-PL-003235
Associated with: CCI-003272
Error handling is the failure to check the return values of functions or catch top level exceptions within a program. Improper error handling in an application can lead to an application failure or possibly result in the application entering an insecure state.
Review the application documentation, code review reports and the results from static code analysis tools. Identify the most recent security scans and code analysis testing conducted. Verify testing configuration includes tests for error handling issues. Check test results for identified error handling vulnerabilities within the application. If the test results indicate the existence of error handling vulnerabilities and no remediation evidence is presented, this is a finding. If no test results are available for review, this is a finding.
Ensure proper return code and exception handling is implemented throughout the application.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer