Files
codeql/java/ql/src/Frameworks/JavaEE/EJB/EjbNative.qhelp
2018-08-30 10:48:05 +01:00

35 lines
652 B
XML

<!DOCTYPE qhelp PUBLIC
"-//Semmle//qhelp//EN"
"qhelp.dtd">
<qhelp>
<overview>
<p>
The Enterprise JavaBeans 3.0 core specification, Section 21.1.2, states:
</p>
<blockquote>
<p>
The enterprise bean must not attempt to load a native library.
</p>
<p>
This function is reserved for the EJB container. Allowing the enterprise bean to load native code would
create a security hole.
</p>
</blockquote>
</overview>
<references>
<li>
<a href="http://jcp.org/aboutJava/communityprocess/final/jsr220/index.html">
JSR-220 Enterprise JavaBeans 3.0 Final Release</a> (ejbcore),
Section 21.1.2 Programming Restrictions
</li>
</references>
</qhelp>