Classes that implement the Externalizable interface must provide the readExternal() and writeExternal() methods. These methods have package access or are public, and so they can be called by trusted and hostile code alike. Consequently, programs must ensure that these methods execute only when intended, and that they cannot overwrite the internal state of objects at arbitrary points during program execution.
This noncompliant code example allows any to reset the value of the object at any time, because the readExternal() method is necessarily declared to be public and lacks protection against hostile callers.
| 
public void readExternal(ObjectInput in) throws IOException, ClassNotFoundException {
   // Read instance fields
   this.name = (String)in.readObject();
   this.UID = in.readInt();
   //...
}
 | 
This compliant solution protects against race-conditions by synchronizing on a private lock object (see LCK00-J. Use private final lock objects to synchronize classes that may interact with untrusted code). It also protects against multiple initialization through the use of a boolean flag that is set after the instance fields have been populated.
| 
private final Object lock = new Object();
private boolean initialized = false;
public void readExternal(ObjectInput in)
 throws IOException, ClassNotFoundException {
  synchronized (lock) {
    if (!initialized) {
      // Read instance fields
      this.name = (String)in.readObject();
      this.UID = in.readInt();
      //...  
      initialized = true;
    } else {
      throw new IllegalStateException();
    }
  }
}
 | 
Note that this compliant solution is insufficient to protect sensitive data.
Failure to prevent the overwriting of externalizable objects can corrupt the state of the object.
| Rule | Severity | Likelihood | Remediation Cost | Priority | Level | 
|---|---|---|---|---|---|
| SER11-J | low | probable | low | P6 | L2 | 
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
| <ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="df041329-3f7f-4047-a574-eafea4a93ea5"><ac:plain-text-body><![CDATA[ | [[API 2006 | AA. Bibliography#API 06]] | 
 | ]]></ac:plain-text-body></ac:structured-macro> | 
| <ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="8f955eb7-f972-45eb-aaaf-4f3bd276b3aa"><ac:plain-text-body><![CDATA[ | [[Sun 2006 | AA. Bibliography#Sun 06]] | "Serialization specification: A.7 Preventing Overwriting of Externalizable Objects" | ]]></ac:plain-text-body></ac:structured-macro> | 
      13. Serialization (SER)      14. Platform Security (SEC)