...
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
References
Wiki Markup |
---|
\[[API 06|AA. Java References#API 06]\] \[[Sun 06|AA. Java References#Sun 06]\] ""Serialization specification: A.7 Preventing Overwriting of Externalizable Objects"" |
...
SER34-J. Make defensive copies of private mutable components 14. Serialization (SER) SER36-J. Do not use the default serialized form for implementation defined invariants