fortify——J2EE Bad Practices: Non-Serializable Object Stored in Session
J2EE错误实践:存储在会话中的非可序列化对象Explanation:J2EE JVM JVM J2EE JVM HttpSession JVM JVMpublic class DataGlob {String globName;String globValue;public void addToSession(HttpSession session) {session.s