...
Wiki Markup |
---|
\[[API 2006|AA. Bibliography#API 06]\] Class {{java.security.AccessController}} \[[MITRE 2009|AA. Bibliography#MITRE 09]\] CWE [272|http://cwe.mitre.org/data/definitions/272.html] |
...
SEC20SEC00-J. Do not expect java.lang.reflect.method.invoke() to behave as the immediate callerAvoid granting excess privileges 02. Platform Security (SEC) 03. Declarations and Initialization (DCL)SEC12-J. Do not grant untrusted code access to classes in inaccessible packages