Common Weakness Enumeration

    CWE Definition / CWE-9

    CWE-9: J2EE Misconfiguration: Weak Access Permissions for EJB Methods

    If elevated access rights are assigned to EJB methods, then an attacker can take advantage of the permissions to exploit the product.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-266: Incorrect Privilege Assignment