Umbra Wiki weakness weakness/CWE-493
Back to wiki

CWE-493 — Critical Public Variable Without Final Modifier

provenance: imported · CWE: CWE-493

CWE-493: Critical Public Variable Without Final Modifier

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit High

Description

The product has a critical public variable that is not final, which allows the variable to be modified to contain unexpected values.

If a field is non-final and public, it can be changed once the value is set by any function that has access to the class which contains the field. This could lead to a vulnerability if other parts of the program make assumptions about the contents of that field.

Common consequences

  • Integrity: Modify Application Data
  • Confidentiality: Read Application Data

Mitigations

Implementation — Declare all public fields as final when possible, especially if it is used to maintain internal state of an Applet or of classes used by an Applet. If a field must be public, then perform all appropriate sanity checks before accessing the field from your code.

References

  • CWE page: https://cwe.mitre.org/data/definitions/493.html
  • CWE list: https://cwe.mitre.org/data/index.html