Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
BIRT Static Code Analysis
gaurav1
<p>Hi , </p><p> </p><p>We are using BIRT 3.7.2 with our Application. </p><p> </p><p>We use Fortify Scan for Static Code Analysis and it has found some issue: </p><p> </p><p>1. Cross Site Scripting DOM : </p><p> The method catchBookmark() in RunFragment.jsp sends unvalidated data to a web browser on line 198, which can result in the browser executing malicious code.</p><p>2. Cross Site Scripting DOM : </p><p> The method debug() in Debug.js sends unvalidated data to a web browser on line 105, which can result in the browser executing malicious code.</p><p>3. Dynamic Code Evaluation: </p><p> The file prototype.js interprets unvalidated user input as source code on line 700. Interpreting user-controlled instructions at run-time can allow attackers to execute malicious code.</p><p>4. Dynamic Code Evaluation:</p><p> The file prototype.js interprets unvalidated user input as source code on line 706. Interpreting user-controlled instructions at run-time can allow attackers to execute malicious code.</p><p> </p><p> </p><p>It would be a great help if some one can help me out in understanding how BIRT mitigates these issue.</p><p> </p><p> </p><p>Thanks,</p><p>Gaurav</p>
Find more posts tagged with
Comments
mwilliams
<p>Please log a bug in the eclipse.org bugzilla for this to see what they have to say.</p>