CWE-493 — Critical Public Variable Without Final Modifier
CWE-493: Critical Public Variable Without Final Modifier
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Variant |
| Status | Draft |
| Likelihood of exploit | High |
Description
The product has a critical public variable that is not final, which allows the variable to be modified to contain unexpected values.
If a field is non-final and public, it can be changed once the value is set by any function that has access to the class which contains the field. This could lead to a vulnerability if other parts of the program make assumptions about the contents of that field.
Common consequences
- Integrity: Modify Application Data
- Confidentiality: Read Application Data
Mitigations
Implementation — Declare all public fields as final when possible, especially if it is used to maintain internal state of an Applet or of classes used by an Applet. If a field must be public, then perform all appropriate sanity checks before accessing the field from your code.
References
- CWE page: https://cwe.mitre.org/data/definitions/493.html
- CWE list: https://cwe.mitre.org/data/index.html