...
Wiki Markup |
---|
\[[Sterbenz 06|AA. Java References#Sterbenz 06]\] \[[MITRE 09|AA. Java References#MITRE 09]\] [CWE ID 302|http://cwe.mitre.org/data/definitions/302.html] "Authentication Bypass by Assumed-Immutable Data" |
...
SEC34SEC03-J. Do not allow tainted variables in doPrivileged blocks 02. Platform Security (SEC) SEC36-J. Enforce security checks in code that performs sensitive operations