CWE-500 - Public Static Field Not Marked Final
- Abstraction:Variant
- Structure:Simple
- Status:Draft
- Release Date:2006-07-19
- Latest Modification Date:2023-06-29
Weakness Name
Public Static Field Not Marked Final
Description
An object contains a public static field that is not marked final, which might allow it to be modified in unexpected ways.
Public static variables can be read without an accessor and changed without a mutator by any classes in the application.
Common Consequences
Scope: Integrity
Impact: Modify Application Data
Notes: The object could potentially be tampered with.
Scope: Confidentiality
Impact: Read Application Data
Notes: The object could potentially allow the object to be read.
Related Weaknesses
OpenAI tests watermarking for ChatGPT-4o Image Generation model
Carding tool abusing WooCommerce API downloaded 34K times on PyPI
Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws
Coinbase to fix 2FA account activity entry freaking out users
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
WinRAR flaw bypasses Windows Mark of the Web security alerts
Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data
Port of Seattle says ransomware breach impacts 90,000 people
PoisonSeed phishing campaign behind emails with wallet seed phrases
CVE-2024-20439 Cisco Smart Licensing Utility Static Credential Vulnerability
CVE-2025-2783 Google Chromium Mojo Sandbox Escape Vulnerability
CVE-2019-9874 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2019-9875 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2025-30154 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
CVE-2025-1316 Edimax IC-7100 IP Camera OS Command Injection Vulnerability
CVE-2024-48248 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability
CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability