CWE-8J2EE Misconfiguration: Entity Bean Declared Remote

PUBLISHEDweakness record
released 2006-07-19 · last modified 2025-12-11

Metadata

CWE ID:
CWE-8
Abstraction:
Variant
Structure:
Simple
Status:
Incomplete
Release Date:
2006-07-19
Latest Modification Date:
2025-12-11

Weakness Name

J2EE Misconfiguration: Entity Bean Declared Remote

Description

When an application exposes a remote interface for an entity bean, it might also expose methods that get or set the bean's data. These methods could be leveraged to read sensitive information, or to change data in ways that violate the application's expectations, potentially leading to other vulnerabilities.

Common Consequences

Scope:
Confidentiality, Integrity
Impact:
Read Application Data, Modify Application Data

Related Weaknesses