Home / Vulnerability Database / Kotlin : Non-serializable object in J2EE session
Kotlin

Kotlin : Non-serializable object in J2EE session

Overview

Saving serializable object in the session may adversely affect the security of the application.

J2EE applications can use multiple JVMs to improve the reliability and performance. For a user to see multiple virtual machines like one, the application duplicates the HttpSession object, so that if one of the virtual machines is unavailable, the other could replace it without disrupting application work.

For correct operation of this mechanism, the values stored in the session must implement the Serializable interface.

LOW

DerScanner Severity Score

Do you want to fix Kotlin : Non-serializable object in J2EE session in your application?

See also

Kotlin

Kotlin : Missing required cryptographic step

Kotlin

Kotlin : Logging into system output

Kotlin

Kotlin : Call of notify() in synchronized block