The J2EE application stores a plaintext password in a configuration file.
Do not hardwire passwords into your software.
Use industry standard libraries to encrypt passwords before storage in configuration files.
Our security experts can help you identify and remediate CWE-555 vulnerabilities in your codebase.
Get Security Assessment