Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9157145
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T12:56:31+00:00 2026-06-17T12:56:31+00:00

I am seeing the below warning form the Fortify SourceAnalyzer for my class which

  • 0

I am seeing the below warning form the Fortify SourceAnalyzer for my class which implements the ISerializer, IDeSerializer interfaces:-

“Missing SecurityManager Check : Serializable”.

This is a security vulnerability because, if you are serializing some sensitive data and have put security manager check in the constructor of the class to avoid unchecked creation of new object instance. You have to override write method and put the same security manager check in the write method as well. (because some one can still create a new instance from the serialized bytes as no java control over object created from the serialized bytes and it will simply deserialize those bytes, so the only way to avoid is to put the same security manager check in the write method).

The above explanation is perfectly fine if i am serializing some sensitive data and have put security mangaer check inside the constructor. But if i have data which is not sensitive and i want to serialize that without any security manager check in the constructor. Still i got the above warning from the Fortify reports. I am not sure how to get rid of this warning, is this a bug in Fortify tool or am i missing something ?

Note:- I do not want any security manager check in my constructor.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T12:56:32+00:00Added an answer on June 17, 2026 at 12:56 pm

    I get a somewhat different explanation from Fortify, since this issue usually does not refer to write, but to read (deserialization). The background is that constructors are not invoked when deserializing data since the runtime takes care of inizalizing the members from the serialized data, so when you have a SecurityManager in your constructor it is not considered when an instance is created by deserializing.

    Anyway, to your question, if you have analyzed the issue and came to the conclusion that it is not an issue, you can mark it as such while auditing the issue. This is possible both in Fortify SSC (the central fortify server) and the Audit Workbench (AWB). In Fortify SSC, go to your issue list, select “View Details” on the particular issue, and in the lower left corner select “Analysis: Not an Issue”. Similar options exist in AWB.

    If you are doing subsequent scans and upload them to the server (or merge them using AWB), Fortify recognizes that this issue has been audited and marked as “not an issue” earlier and keeps the “not an issue” information.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I wrote a multithreaded program in which I am seeing some weird behavior. Below
My code is below: I am seeing that on running the app the loadWidget
I am seeing an intriguing situation rounding Currency in C# (VS 2008 SP1). Below
When reading two dates from a binary file I'm seeing the error below: The
When i execute the below code,I am seeing the output as: Finally Exception in
In the code below, I am seeing the tunneling events occurring but am not
In the function below, I'm seeing to sort the array by alpha. However, it
So I have created some demo code, see below. What I am seeing is
Consider the code below which compiles and runs without error in Delphi 6. When
I run the following command and am seeing the below issue... $ sudo gem

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.