CWE-245 - J2EE Bad Practices: Direct Management of Connections
- Abstraction:Variant
- Structure:Simple
- Status:Draft
- Release Date:2006-07-19
- Latest Modification Date:2023-06-29
Weakness Name
J2EE Bad Practices: Direct Management of Connections
Description
The J2EE application directly manages connections, instead of using the container's connection management facilities.
The J2EE standard forbids the direct management of connections. It requires that applications use the container's resource management facilities to obtain connections to resources. Every major web application container provides pooled database connection management as part of its resource management framework. Duplicating this functionality in an application is difficult and error prone, which is part of the reason it is forbidden under the J2EE standard.
Common Consequences
Scope: Other
Impact: Quality Degradation
Related Weaknesses
OpenAI tests watermarking for ChatGPT-4o Image Generation model
Carding tool abusing WooCommerce API downloaded 34K times on PyPI
Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws
Coinbase to fix 2FA account activity entry freaking out users
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
WinRAR flaw bypasses Windows Mark of the Web security alerts
Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data
Port of Seattle says ransomware breach impacts 90,000 people
PoisonSeed phishing campaign behind emails with wallet seed phrases
CVE-2024-20439 Cisco Smart Licensing Utility Static Credential Vulnerability
CVE-2025-2783 Google Chromium Mojo Sandbox Escape Vulnerability
CVE-2019-9874 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2019-9875 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2025-30154 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
CVE-2025-1316 Edimax IC-7100 IP Camera OS Command Injection Vulnerability
CVE-2024-48248 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability
CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
InformationalInformation Disclosure - Suspicious Comments
HighPII Disclosure