If elevated access rights are assigned to EJB methods, then an attacker can take advantage of the permissions to exploit the product.
Follow the principle of least privilege when assigning access rights to EJB methods. Permission to invoke EJB methods should not be granted to the ANYONE role.
Our security experts can help you identify and remediate CWE-9 vulnerabilities in your codebase.
Get Security Assessment