Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 4.0

...

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

SER04-J

high

probable

high

P6

L2

Related Guidelines

Secure Coding Guidelines for the Java Programming Language, Version 3.0

Guideline 5-4. Duplicate the SecurityManager checks enforced in a class during serialization and deserialization

Bibliography

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="afbf131d-0a2b-4b8d-a23f-cb23eb742310"><ac:plain-text-body><![CDATA[

[ [Long 2005AA. References#Long 05] ]

Section 2.4, Serialization ]]></ac:plain-text-body></ac:structured-macro>

...

SER03-J. Do not serialize unencrypted, sensitive data      13. Serialization (SER)