The JAR files that compose the application are not correctly signed, allowing an attacker to modify the code withouth raising alerts on an integrity check.
Inject malicious code in the application without raising alerts.
Sign the application JAR files using a trusted key.
Anonymous attacker from Internet with access to the JAR Files.
⌚ 90 minutes.
Default score using CVSS 3.1. It may change depending on the context of the src.
Default score using CVSS 4.0. It may change depending on the context of the src.
Sign all the JAR files of the application with a certified key tool
jarsigner -keystore NONE -certchain "bundle.pem" -tsa "http://time.certum.pl" -storetype PKCS11
-providerClass sun.security.pkcs11.SunPKCS11 -providerArg "provider.cfg"
-storepass "[your_pin]" "[your_code].jar" "[your_alias]"
The source code has .jar files that were not signed before runtime, please check to verify before compiling