| OWASP Category | CWE ID | Parasoft Rule IDs |
|---|
| A1 Injection | CWE-77: Command Injection | |
| A1 Injection | CWE-89: SQL Injection | |
| A3 Sensitive Data Exposure | CWE-326: Weak Encryption | |
| A3 Sensitive Data Exposure | CWE-327: Use of a Broken or Risky Cryptographic Algorithm | - SECURITY-02
- SECURITY-28
- SECURITY-37
|
| A5 Broken Access Control | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| A6 Security Misconfiguration | CWE-391: Unchecked Error Condition | |
| A6 Security Misconfiguration | CWE-396: Declaration of Catch for Generic Exception | |
| A10 Insufficient Logging & Monitoring | CWE-223: Omission of Security-relevant Information
| |