CWE-1069 Variante Incompleto

Empty Exception Block

This weakness occurs when a try-catch or try-finally block is present but contains no code to handle the caught exception or perform cleanup.

Definição

What is CWE-1069?

This weakness occurs when a try-catch or try-finally block is present but contains no code to handle the caught exception or perform cleanup.
Empty exception blocks silently swallow errors, making debugging extremely difficult. The program appears to run normally, but underlying failures—like a failed database connection or a corrupted file read—go unreported, leading to unpredictable behavior and corrupted data states. From a security perspective, this reliability flaw can become a vulnerability if an attacker can trigger the exception. By suppressing critical error messages, empty catch blocks can hide the symptoms of an ongoing attack, such as authentication bypass attempts or injection attacks, allowing malicious activity to continue undetected.
Impacto no mundo real

Real-world CVEs caused by CWE-1069

Ainda não há referências CVE públicas associadas a este CWE no catálogo da MITRE.

Como os atacantes a exploram

Trajeto do atacante passo a passo

  1. 1

    In the following Java example, the code catches an ArithmeticException.

  2. 2

    Since the exception block is empty, no action is taken.

  3. 3

    In the code below the exception has been logged and the bad execution has been handled in the desired way allowing the program to continue in an expected way.

Exemplo de código vulnerável

Vulnerable Java

In the following Java example, the code catches an ArithmeticException.

Vulnerável Java
public class Main {
  	public static void main(String[] args) { 
  		int a = 1; 
  		int b = 0; 
  		int c = 0;
  		try { 
  			c = a / b;
  		} catch(ArithmeticException ae) { 
  		}
  	}
  }
Exemplo de código seguro

Secure Java

In the code below the exception has been logged and the bad execution has been handled in the desired way allowing the program to continue in an expected way.

Seguro Java
public class Main {
  	public static void main(String[] args) { 
  		int a = 1; 
  		int b = 0; 
  		int c = 0;
  		try { 
  			c = a / b;
  		} catch(ArithmeticException ae) { 
  			log.error("Divided by zero detected, setting to -1."); 
  			c = -1;
  		}
  	}
  }
What changed: the unsafe sink is replaced (or the input is validated/escaped) so the same payload no longer triggers the weakness.
Lista de verificação de prevenção

How to prevent CWE-1069

  • Implementation For every exception block add code that handles the specific exception in the way intended by the application.
Sinais de deteção

How to detect CWE-1069

SAST High

Executar análise estática (SAST) na base de código à procura do padrão inseguro no fluxo de dados.

DAST Moderate

Executar testes dinâmicos de segurança de aplicações (DAST) contra o endpoint em execução.

Runtime Moderate

Monitorizar os registos em tempo de execução para traços de exceção invulgares, input malformado ou tentativas de contornar a autorização.

Code review Moderate

Revisão de código: sinalizar qualquer novo código que trate input desta superfície sem usar os ajudantes validados do framework.

CWE-1069

Don't catalog this weakness. Prove it's reachable.

Plexicus turns CWE catalogs into evidence: every CWE-pattern is matched against your real code graph, reach is proven on a sandbox clone, and verified findings ship as reviewed PRs.

Perguntas frequentes

Frequently asked questions

O que é o CWE-1069?

This weakness occurs when a try-catch or try-finally block is present but contains no code to handle the caught exception or perform cleanup.

Qual a gravidade do CWE-1069?

A MITRE não publicou uma classificação de probabilidade de exploração para esta fraqueza. Trate-a como impacto médio até o seu modelo de ameaças provar o contrário.

Que linguagens ou plataformas são afetadas pelo CWE-1069?

A MITRE não especificou as plataformas afetadas por este CWE — pode aplicar-se à maioria das stacks de aplicações.

Como posso prevenir o CWE-1069?

For every exception block add code that handles the specific exception in the way intended by the application.

Como é que o Plexicus deteta e corrige o CWE-1069?

O motor SAST do Plexicus correlaciona a assinatura de fluxo de dados do CWE-1069 em cada commit. Quando é encontrada uma correspondência, o nosso agente Codex Remedium abre um PR de correção com o código corrigido, testes e um resumo de uma linha para o revisor.

Onde posso saber mais sobre o CWE-1069?

A MITRE publica a definição canónica em https://cwe.mitre.org/data/definitions/1069.html. Pode também consultar a documentação da OWASP e do NIST para orientações adjacentes.

Pronto para validar o que importa?

Pronto para validar o que importa.

O Plexicus é Proof-Driven AppSec: achados validados, compreensão contextual e remediação revisada — ancorada em evidência, escopada com você.

Qualificação

Verifique se o AI Swarm Pentest se adequa ao seu ambiente.

Partilhe o contexto mínimo. Vamos rever o escopo e indicar o próximo passo comercial.

Antes de enviar — verifique se se encaixa

0 / 280

Sem compromisso. Se não se encaixa, dizemos.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Ronda privada Para investidores