CWE-487: Reliance on Package-level Scope
Java packages are not inherently closed; therefore, relying on them for code security is not a good practice.
How it's found
Reliance on Package-level Scope is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
The purpose of package scope is to prevent accidental access by other parts of a program. This is an ease-of-software-development feature but not a security feature.
Consequences
- Read Application Data: Any data in a Java package can be accessed outside of the Java framework if the package is distributed.
- Modify Application Data: The data in a Java class can be modified by anyone outside of the Java framework if the package is distributed.
Mitigations
- Architecture and Design/Implementation: Data should be private static and final whenever possible. This will assure that your code is protected by instantiating early, preventing access and tampering.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is CWE-487?
Java packages are not inherently closed; therefore, relying on them for code security is not a good practice.
How do you find Reliance on Package-level Scope?
Reliance on Package-level Scope is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-487?
Read Application Data: Any data in a Java package can be accessed outside of the Java framework if the package is distributed. Modify Application Data: The data in a Java class can be modified by anyone outside of the Java framework if the package is distributed.
Does TurboPentest test for Reliance on Package-level Scope?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related CWEs
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest