Java


JAVA.INSEC.SAC : Security Annotation Conflict (Java)

Summary

Detected possible security annotation conflict.

Properties

Class Name Security Annotation Conflict (Java)
Significance security
Mnemonic JAVA.INSEC.SAC
Categories
CWE CWE:749 Exposed Dangerous Method or Function
OWASP-2017 OWASP-2017:A2 Broken authentication
  OWASP-2017:A5 Broken access control
OWASP-2021 OWASP-2021:A1 Broken access control
  OWASP-2021:A7 Identification and authorization failures
Availability Available for Java only.
Enabling Checks for this warning class are disabled by default. To enable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += allow class="Security Annotation Conflict (Java)"

Resolution

Parameterize it in a configuration file.

Use safer protocols.

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.