...
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
Related Guidelines
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="c003017c-1fd5-4e19-90cc-c0fd1f7de2f8"><ac:plain-text-body><![CDATA[ | [[MITRE 2009 | AA. Bibliography#MITRE 09]] | [CWE ID 300 | http://cwe.mitre.org/data/definitions/300.html] "Channel Accessible by Non-Endpoint (aka 'Man-in-the-Middle')" | ]]></ac:plain-text-body></ac:structured-macro> |
| CWE ID 319 "Cleartext Transmission of Sensitive Information" | ||||
| CWE ID 494 "Download of Code Without Integrity Check" | ||||
| CWE ID 347 "Improper Verification of Cryptographic Signature" |
Bibliography
<ac:structured-macro ac:name="unmigrated-wiki-markup |
...
" ac:schema-version="1" ac:macro-id="5ae91c96-e906-4c93-82ed-e138e04926d5"><ac:plain-text-body><![CDATA[ | [[API |
...
2006 |
...
AA. |
...
Bibliography#API |
...
06]] |
| ] |
...
]></ac:plain-text-body></ac:structured-macro> | ||||
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="bfd76b61-00c6-46f2-8246-a019b148174c"><ac:plain-text-body><![CDATA[ | [[Bea 2008 | AA. Bibliography#Bea 08]] |
| ]]></ac:plain-text-body></ac:structured-macro> |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="84432134-fde2-4dc7-b539-37efcad24f88"><ac:plain-text-body><![CDATA[ | [[Eclipse 2008 | AA. Bibliography#Eclipse 08]] | [JAR Signing | http://wiki.eclipse.org/JAR_Signing] |
...
and |
...
[Signed |
...
bundles |
...
and |
...
protecting |
...
against |
...
malicious |
...
code |
...
http://help.eclipse.org/stable/index.jsp?topic=/org.eclipse.platform.doc.isv/guide] |
...
]]></ac:plain-text-body></ac:structured-macro> | |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="dd870888-f980-498c-a264-8578d44043c5"><ac:plain-text-body><![CDATA[ | [[Fairbanks |
...
07 |
...
AA. |
...
Bibliography#Fairbanks |
...
07] |
...
] |
| ]]></ac:plain-text-body></ac:structured-macro> | |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e2d8db23-ba4a-483c-a8ef-c26b7f23a820"><ac:plain-text-body><![CDATA[ | [[Flanagan 2005 | AA. Bibliography#Flanagan 05]] | Chapter 24. The java.util.jar |
...
Package | ]]></ac:plain-text-body></ac:structured-macro> | ||
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="9921ff57-4ee4-4cf5-a57b-6cd89465f9be"><ac:plain-text-body><![CDATA[ | [[Gong 2003 | AA. Bibliography#Gong 03]] | 12.8.3 |
...
jarsigner | ]]></ac:plain-text-body></ac:structured-macro> | ||||
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="47713439-c775-46b1-986b-f3a89f8de3a9"><ac:plain-text-body><![CDATA[ | [[Halloway 2001 | AA. Bibliography#Halloway 01]] |
| ]]></ac:plain-text-body></ac:structured-macro> | |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="5f1eaa87-2b0f-4941-8113-76772a7b036f"><ac:plain-text-body><![CDATA[ | [[JarSpec 2008 | AA. Bibliography#JarSpec 08]] | Signature Validation |
| ]]></ac:plain-text-body></ac:structured-macro> |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="51501ad5-3baa-4141-abec-609c18c99325"><ac:plain-text-body><![CDATA[ | [[Oaks 2001 | AA. Bibliography#Oaks 01]] | Chapter 12: Digital Signatures, Signed Classes | ]]></ac:plain-text-body></ac:structured-macro> | |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e33a2918-ba7a-4d3e-a436-9461960ce5ae"><ac:plain-text-body><![CDATA[ | [[Muchow 2001 | AA. Bibliography#Muchow 01]] |
| ]]></ac:plain-text-body></ac:structured-macro> | |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="96b3b8e1-02fb-4f1b-8ccc-847452b834b9"><ac:plain-text-body><![CDATA[ | [[Tutorials 2008 | AA. Bibliography#Tutorials 08]] | [The JarRunner Class | http://java.sun.com/docs/books/tutorial/deployment/jar/jarrunner.html], |
...
[Lesson: |
...
API |
...
and |
...
Tools |
...
Use |
...
for |
...
Secure |
...
Code |
...
and |
...
File |
...
Exchanges |
...
http://java.sun.com/docs/books/tutorial/security/sigcert/index.html] |
...
and |
...
[Verifying |
...
Signed |
...
JAR |
...
Files |
...
http://java.sun.com/docs/books/tutorial/deployment/jar/verify.html] | ]]></ac:plain-text-body></ac:structured-macro> |
...
SEC18-J. Define wrappers around sensitive native methods 14. Platform Security (SEC) SEC21-J. Remove superfluous code from privileged blocks