Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Not specific to Java, so removed '-J' from end of rule

(THIS CODING RULE OR GUIDELINE IS UNDER CONSTRUCTION)

Information that is cached may become accessible to other applications, and certainly becomes accessible if the device is found or stolen by a third party.

...

[This rule may require four or five NCCE/CS pairs.]

Noncompliant Code Example

This noncompliant code example shows an application that caches sensitive information.

...

Another application could access the cache, thereby revealing the sensitive information.

Compliant Solution

In this compliant solution the sensitive information is not cached.

Code Block
bgColor#CCCCFF
TBD

Risk Assessment

Caching sensitive information may result in the information becoming accessible.

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

DRD22-J

Medium

Probable

High

P4

L3

Automated Detection

It is not possible to automatically detect all situations when sensitive information may be cached.

Bibliography