From 1fd2be3879a242b0a2a5be8d2dff2d2f84bfbfe5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timo=20M=C3=BCller?= Date: Tue, 4 May 2021 13:57:19 +0200 Subject: [PATCH] Added more clear reference Co-authored-by: Marcono1234 --- .../CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.qhelp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.qhelp b/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.qhelp index 670d961e881..4ce48b010ca 100644 --- a/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.qhelp +++ b/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.qhelp @@ -63,6 +63,6 @@ For this reason an initialization with a null environment is also v
  • Issue discovered in Tomcat (CVE-2016-8735): OWASP ESAPI.
  • Vulnerable implementation of the RMI "newClient()" function: Vulnerable Function.
  • Oracle release notes fixing the issue: Rlease Notes.
  • -
  • Documentation for CREDENTIALS_FILTER_PATTERN
  • +
  • Java API Specification: RMIConnectorServer.CREDENTIALS_FILTER_PATTERN