Skip to main content
assistive.skiplink.to.breadcrumbs
assistive.skiplink.to.header.menu
assistive.skiplink.to.action.menu
assistive.skiplink.to.quick.search
Log in
Confluence
Spaces
Hit enter to search
Help
Online Help
Keyboard Shortcuts
Feed Builder
What’s new
Available Gadgets
About Confluence
Log in
SEI CERT Oracle Coding Standard for Java
Pages
Boards
Space shortcuts
Dashboard
Secure Coding Home
Android
C
C++
Java
Perl
Page tree
Browse pages
Configure
Space tools
View Page
A
t
tachments (0)
Page History
Page Information
View in Hierarchy
View Source
Export to PDF
Export to Word
Pages
…
SEI CERT Oracle Coding Standard for Java
2 Rules
Rule 49. Miscellaneous (MSC)
MSC11-J. Do not let session information leak within a servlet
Page Information
Title:
MSC11-J. Do not let session information leak within a servlet
Author:
David Svoboda
Jun 17, 2014
Last Changed by:
G. Ann Campbell
Jul 21, 2017
Tiny Link:
(useful for email)
https://wiki.sei.cmu.edu/confluence/x/2TZGBQ
Export As:
Word
·
PDF
Incoming Links
SEI CERT Oracle Coding Standard for Java (1)
Page:
MSC10-J. Do not use OAuth 2.0 implicit grant (unmodified) for authentication
Hierarchy
Parent Page
Page:
Rule 49. Miscellaneous (MSC)
Labels
Global Labels (4)
draft
incomplete
rule
msc
Recent Changes
Time
Editor
Jul 21, 2017 10:12
G. Ann Campbell
View Changes
Feb 26, 2016 11:24
G. Ann Campbell
View Changes
Jul 13, 2015 09:28
Carol J. Lallier
View Changes
Jul 13, 2015 09:20
Carol J. Lallier
View Changes
Dec 15, 2014 11:00
Fred Long
View Page History
Outgoing Links
External Links (7)
cwe.mitre.org/
docs.oracle.com/javaee/6/api/index.html?javax/servlet/http/…
www.hpenterprisesecurity.com/vulncat/en/vulncat/java/single…
https://www.sonarsource.com/products/codeanalyzers/sonarjav…
tomcat.apache.org/
cwe.mitre.org/data/definitions/543.html
https://www.securecoding.cert.org/confluence/pages/viewpage…
SEI CERT Oracle Coding Standard for Java (10)
Page:
Rule AA. References
Page:
LCK00-J. Use private final lock objects to synchronize classes that may interact with untrusted code
Page:
VNA01-J. Ensure visibility of shared references to immutable objects
Home page:
SEI CERT Oracle Coding Standard for Java
Page:
Rule 50. Android (DRD)
Page:
Rule BB. Glossary
Page:
SonarQube
Page:
MSC07-J. Prevent multiple instantiations of singleton objects
Page:
SonarQube_V
Page:
MSC10-J. Do not use OAuth 2.0 implicit grant (unmodified) for authentication
Overview
Content Tools
{"serverDuration": 65, "requestCorrelationId": "d8ecc2ec6017c1f4"}