...
http://owasp-esapi-java.googlecode.com/svn/trunk_doc/latest/org/owasp/esapi/AccessReferenceMap.html
...
4.2. Check access.
...
Each use of a direct object reference from an untrusted source must include an access control check to ensure the user is authorized for the requested object.
...