Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Code Block
bgColor#CCCCFF
 

Risk Assessment

If non-serializable nonserializable objects are stored as attributes in an HTTP session then ...

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

MSC08-J

Low

Probable

High

P2

L3

Automated Detection

TBD

Bibliography

[Fortify 2014]Fortify Diagnostic
 HTTPSession J2EE Documentation [Note. This is a JavaEE 5 reference. I cannot find the corresponding API in Java 7.]

 

...

Image Modified