This rule is defined by the following Java class: net.sourceforge.pmd.rules.sunsecure.ArrayIsStoredDirectly
Example:
public class Foo { private String [] x; public void foo (String [] param) { // Don't do this, make a copy of the array at least this.x=param; } }