OWASP Category | CWE ID | Parasoft Rule IDs |
---|---|---|
A1 Injection | CWE-77: Command Injection |
|
A1 Injection | CWE-89: SQL Injection |
|
A3 Sensitive Data Exposure | CWE-326: Weak Encryption |
|
A3 Sensitive Data Exposure | CWE-327: Use of a Broken or Risky Cryptographic Algorithm |
|
A5 Broken Access Control | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|
A6 Security Misconfiguration | CWE-391: Unchecked Error Condition |
|
A6 Security Misconfiguration | CWE-396: Declaration of Catch for Generic Exception |
|
A10 Insufficient Logging & Monitoring | CWE-223: Omission of Security-relevant Information |
|