...
Rule | Severity | Likelihood | Remediation Cost | Priority | Level |
|---|---|---|---|---|---|
SEC06-J | High | Probable | Medium | P12 | L1 |
Automated Detection
Automated detection is not feasible in the fully general case. However, an approach similar to Design Fragments [Fairbanks 2007] could assist both programmers and static analysis tools.
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CodeSonar |
| JAVA.IO.INJ.ANDROID.MESSAGE | Android Message Injection (Java) |
Related Guidelines
| ISO/IEC TR 24772:2010 | Improperly Verified Signature [XZR] |
CWE-300, Channel Accessible by Non-endpoint (aka "Man-in-the-Middle") |
...