Umbra Wiki weakness weakness/CWE-499
Back to wiki

CWE-499 — Serializable Class Containing Sensitive Data

provenance: imported · CWE: CWE-499

CWE-499: Serializable Class Containing Sensitive Data

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit High

Description

The code contains a class with sensitive data, but the class does not explicitly deny serialization. The data can be accessed by serializing the class through another class.

Serializable classes are effectively open classes since data cannot be hidden in them. Classes that do not explicitly deny serialization can be serialized by any other class, which can then in turn use the data stored inside it.

Common consequences

  • Confidentiality: Read Application Data

Mitigations

Implementation — In Java, explicitly define final writeObject() to prevent serialization. This is the recommended solution. Define the writeObject() function to throw an exception explicitly denying serialization.

Implementation — Make sure to prevent serialization of your objects.

References

  • CWE page: https://cwe.mitre.org/data/definitions/499.html
  • CWE list: https://cwe.mitre.org/data/index.html