CWE-9: J2EE Misconfiguration: Weak Access Permissions for EJB Methods
If elevated access rights are assigned to EJB methods, then an attacker can take advantage of the permissions to exploit the product.
Browse cwe in architecture and design system configuration with official CWE context and Glexia analysis.
Search And Filters
Showing 6 of 6 CWE records.
If elevated access rights are assigned to EJB methods, then an attacker can take advantage of the permissions to exploit the product.
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
If an include file source is accessible, the file can contain usernames and passwords, as well as sensitive information pertaining to the application and system.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Certain conditions, such as network failure, will cause a server error message to be displayed.
An ActiveX control is intended for use in a web browser, but it exposes dangerous methods that perform actions that are outside of the browser's security model (e.g. the zone or domain).