CWE-487: Reliance on Package-level Scope
Java packages are not inherently closed; therefore, relying on them for code security is not a good practice.
How it's found
Reliance on Package-level Scope is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
The purpose of package scope is to prevent accidental access by other parts of a program. This is an ease-of-software-development feature but not a security feature.
Consequences
- Read Application Data: Any data in a Java package can be accessed outside of the Java framework if the package is distributed.
- Modify Application Data: The data in a Java class can be modified by anyone outside of the Java framework if the package is distributed.
Mitigations
- Architecture and Design/Implementation: Data should be private static and final whenever possible. This will assure that your code is protected by instantiating early, preventing access and tampering.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-487?
Java packages are not inherently closed; therefore, relying on them for code security is not a good practice.
How do you find Reliance on Package-level Scope?
Reliance on Package-level Scope is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-487?
Read Application Data: Any data in a Java package can be accessed outside of the Java framework if the package is distributed. Modify Application Data: The data in a Java class can be modified by anyone outside of the Java framework if the package is distributed.
Does TurboPentest test for Reliance on Package-level Scope?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest