Skip to main content

9.7.6 Resolved Issues List

Notice

  • critical_icon.png = Critical Severity

  • High_Severity.png = High Severity

  • Medium_Severity.png = Medium Severity

  • Low_Severity.png = Low Severity

All

  • High_Severity.png: Resolved an issue where the Engine Configuration Exporter BAT file used the wrong .NET version.

  • High_Severity.png: Resolved inconsistencies in log messages that appeared while parsing files.

  • Medium_Severity.png: Resolved the deprecation issue related to Deserialization_of_Untrusted_Data.

  • Medium_Severity.png: Resolved a problem where results were not displayed after canceling and running a new query.

  • Medium_Severity.png: Resolved minor efficiency issues in cxXPath.FindXmlAttributesByNameAndValue.

  • Medium_Severity.png: Resolved a Docker Linux issue when using environments with more than 100GB RAM, including new FIPS implementation.

  • Medium_Severity.png: Resolved a false negative for Java_Android.Hardcoded_Password_In_Gradle.

  • Medium_Severity.png: Resolved inconsistent behavior in cxXPath.FindXmlAttributesByNameAndValue, reproduced with Java.

Apex

  • High_Severity.png: Resolved a false positive for FLS_Create_Partial() and FLS_Update_Partial() during upsert operations using AccessLevel.USER_MODE.

  • High_Severity.png: Resolved a false positive for Sharing() caused by a missing custom attribute.

  • High_Severity.png: Resolved a false positive for FLS_Create() triggered by validation inside a function.

  • Medium_Severity.png: Resolved issues related to preprocessing comments in JS Apex pages.

ASP

  • Medium_Severity.png: Resolved duplicated results in ASP_Critical_Risk.Stored_XSS.

  • Medium_Severity.png: Resolved a false negative for ASP_High_Risk.Reflected_XSS_All_Clients.

  • Low_Severity.png: Resolved incorrect line pragma generation for many nodes, which corrupted results across multiple queries.

C / CPP

  • Medium_Severity.png: Resolved a false positive for CPP_Medium_Threat.Divide_By_Zero.

  • Medium_Severity.png: Resolved a false negative for CPP_Buffer_Overflow.Buffer_Overflow_Unbounded_Buffer.

C

  • Medium_Severity.png: Resolved a false positive for SQL Injection in ESQL/C.

C / CPP (MISRA)

  • Medium_Severity.png: Resolved an issue where MISRA Query 11.X incorrectly flagged results involving IndexerRef.

Cobol

  • Medium_Severity.png: Resolved an Antlr4.Runtime.NoViableAltException error.

CPP

  • critical_icon.png: Resolved failures in the FIS project through targeted improvements.

  • High_Severity.png: Resolved a false positive for Use_After_Free() caused by confusion between freeing arrays and freeing array elements.

  • High_Severity.png: Resolved a false positive for MemoryFree_on_StackVariable.

  • High_Severity.png: Resolved jumping results that appeared across multiple queries.

  • High_Severity.png: Resolved a false positive in Process_Control.

  • High_Severity.png: Resolved an issue where a folder caused the entire scan to fail.

  • High_Severity.png: Resolved inconsistent scan results across multiple runs of the same project.

  • High_Severity.png: Resolved several jump-result issues in CPP projects.

  • High_Severity.png: Resolved a false positive for Buffer_Overflow_AddressOfLocalVarReturned().

  • Medium_Severity.png: Resolved missing descriptions in several CPP queries.

  • Medium_Severity.png: Resolved a false positive for Buffer_Improper_Index_Access.

  • Medium_Severity.png: Resolved a false positive for MemoryFree_on_StackVariable().

  • Medium_Severity.png: Resolved a false positive for Use_of_Uninitialized_Variable where constructor initialization was not detected.

  • Medium_Severity.png: Resolved another false positive for MemoryFree_on_StackVariable.

  • Medium_Severity.png: Resolved a false negative for Buffer_Improper_Index_Access.

  • Medium_Severity.png: Resolved a false positive for Buffer_Overflow_Wrong_Buffer_Size by adding .length() as a sanitizer.

  • Medium_Severity.png: Resolved description issues in Improper_Resource_Access_Authorization.

  • Low_Severity.png: Resolved a false positive for Buffer_Improper_Index_Access.

CSharp

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.Command_Injection() caused by safe ProcessStartInfo usage.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.SQL_Injection() involving LINQ‑to‑SQL sanitization.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.XSS() triggered by safe HtmlEncode usage.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.LDAP_Injection() caused by safe DirectorySearcher filters.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.Path_Traversal() involving validated file paths.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.XSS() caused by safe Razor encoding.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.OS_Command() triggered by safe ProcessStartInfo arguments.

  • High_Severity.png: Resolved a false positive for CSharp_Critical_Risk.SQL_Injection() caused by safe EF Core parameterization.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Reflected_XSS() involving safe MVC model binding.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Stored_XSS() caused by safe HTML sanitization.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Path_Traversal() involving safe Path.Combine usage.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Command_Injection() triggered by safe ProcessStartInfo.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.SQL_Injection() involving safe EF Core queries.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.XSS() caused by safe Razor encoding.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.OS_Command() involving safe ProcessStartInfo.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.LDAP_Injection() caused by safe DirectorySearcher filters.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Reflected_XSS() involving safe HtmlEncode.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for CSharp_High_Risk.Command_Injection() involving safe arguments.

  • Low_Severity.png: Resolved a false positive for CSharp_Low_Risk.Information_Leak() caused by benign debug output.

  • Low_Severity.png: Resolved a false positive for CSharp_Low_Risk.Log_Injection() involving safe logging patterns.

GO

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.Command_Injection() caused by safe exec.Command usage.

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.SQL_Injection() involving safe parameterized queries.

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.Path_Traversal() caused by validated file paths.

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.SSRF() involving safe URL parsing.

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.XSS() caused by safe template escaping.

  • High_Severity.png: Resolved a false positive for GO_Critical_Risk.OS_Command() involving safe argument construction.

  • Medium_Severity.png: Resolved a false positive for GO_High_Risk.Reflected_XSS() involving safe HTML escaping.

  • Medium_Severity.png: Resolved a false positive for GO_High_Risk.Stored_XSS() caused by safe sanitization.

  • Medium_Severity.png: Resolved a false positive for GO_High_Risk.Path_Traversal() involving validated paths.

Java

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.SQL_Injection() caused by safe PreparedStatement usage.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.Command_Injection() involving safe Runtime.exec arguments.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.XSS() caused by safe JSP/Servlet encoding.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.LDAP_Injection() involving safe filter construction.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.Path_Traversal() caused by validated file paths.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.SSRF() involving safe URL validation.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.OS_Command() caused by safe ProcessBuilder usage.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.Expression_Language_Injection() involving safe EL evaluation.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.XSS() caused by safe JSF encoding.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.SQL_Injection() involving safe ORM parameterization.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.Path_Traversal() involving safe canonicalization.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.SSRF() caused by safe URL construction.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.Command_Injection() involving safe argument handling.

  • High_Severity.png: Resolved a false positive for Java_Critical_Risk.LDAP_Injection() involving safe directory queries.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Reflected_XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Command_Injection() involving safe ProcessBuilder.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.OS_Command() involving safe exec usage.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.LDAP_Injection() involving safe filters.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Expression_Language_Injection() involving safe EL evaluation.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SSRF() involving safe URL validation.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.XSS() involving safe JSF encoding.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Stored_XSS() involving safe HTML escaping.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Reflected_XSS() involving safe JSP encoding.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SQL_Injection() involving safe ORM queries.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Path_Traversal() involving canonicalization.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Command_Injection() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.OS_Command() involving safe ProcessBuilder.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.LDAP_Injection() involving safe directory queries.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Expression_Language_Injection() involving safe EL usage.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SSRF() involving safe URL parsing.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Reflected_XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Command_Injection() involving safe exec usage.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.OS_Command() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.LDAP_Injection() involving safe filters.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.Expression_Language_Injection() involving safe EL evaluation.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.SSRF() involving safe URL validation.

  • Medium_Severity.png: Resolved a false positive for Java_High_Risk.XSS() involving safe JSP encoding.

  • Low_Severity.png: Resolved a false positive for Java_Low_Risk.Information_Leak() involving benign debug output.

  • Low_Severity.png: Resolved a false positive for Java_Low_Risk.Log_Injection() involving safe logging patterns.

JavaScript

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.XSS() involving safe DOMPurify usage.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.Command_Injection() involving safe child_process.exec arguments.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.SQL_Injection() involving safe parameterized queries.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.SSRF() involving safe URL validation.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.Path_Traversal() involving safe path normalization.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.OS_Command() involving safe execFile usage.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.XSS() involving safe template escaping.

  • High_Severity.png: Resolved a false positive for JavaScript_Critical_Risk.Expression_Injection() involving safe eval alternatives.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Reflected_XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Command_Injection() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.OS_Command() involving safe execFile usage.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.SSRF() involving safe URL parsing.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Stored_XSS() involving safe HTML escaping.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Reflected_XSS() involving safe DOM manipulation.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.SQL_Injection() involving safe ORM queries.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Path_Traversal() involving canonicalization.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.Command_Injection() involving safe exec usage.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.OS_Command() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.SSRF() involving safe URL validation.

  • Medium_Severity.png: Resolved a false positive for JavaScript_High_Risk.XSS() involving safe template escaping.

  • Low_Severity.png: Resolved a false positive for JavaScript_Low_Risk.Information_Leak() involving benign debug output.

  • Low_Severity.png: Resolved a false positive for JavaScript_Low_Risk.Log_Injection() involving safe logging patterns.

Kotlin

  • High_Severity.png: Resolved a false positive for Kotlin_Critical_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for Kotlin_High_Risk.XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for Kotlin_High_Risk.Path_Traversal() involving validated paths.

PHP

  • High_Severity.png: Resolved a false positive for PHP_Critical_Risk.SQL_Injection() involving safe PDO parameterization.

  • High_Severity.png: Resolved a false positive for PHP_Critical_Risk.Command_Injection() involving safe escapeshellarg usage.

  • High_Severity.png: Resolved a false positive for PHP_Critical_Risk.XSS() involving safe htmlspecialchars usage.

  • Medium_Severity.png: Resolved a false positive for PHP_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for PHP_High_Risk.Reflected_XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for PHP_High_Risk.Path_Traversal() involving validated paths.

PLSQL

  • High_Severity.png: Resolved a false positive for PLSQL_Critical_Risk.SQL_Injection() involving safe bind variables.

  • Medium_Severity.png: Resolved a false positive for PLSQL_High_Risk.Stored_XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for PLSQL_High_Risk.Reflected_XSS() involving safe sanitization.

Python

  • High_Severity.png: Resolved a false positive for Python_Critical_Risk.Command_Injection() involving safe subprocess usage.

  • High_Severity.png: Resolved a false positive for Python_Critical_Risk.SQL_Injection() involving safe parameterized queries.

  • High_Severity.png: Resolved a false positive for Python_Critical_Risk.Path_Traversal() involving validated file paths.

  • High_Severity.png: Resolved a false positive for Python_Critical_Risk.OS_Command() involving safe argument handling.

  • High_Severity.png: Resolved a false positive for Python_Critical_Risk.SSRF() involving safe URL validation.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Reflected_XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Stored_XSS() involving safe sanitization.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.SQL_Injection() involving safe ORM parameterization.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Path_Traversal() involving canonicalization.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Command_Injection() involving safe subprocess arguments.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.OS_Command() involving safe exec usage.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.SSRF() involving safe URL parsing.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.XSS() involving safe template escaping.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Stored_XSS() involving safe HTML escaping.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Reflected_XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.Command_Injection() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.OS_Command() involving safe subprocess usage.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.SSRF() involving safe URL validation.

  • Medium_Severity.png: Resolved a false positive for Python_High_Risk.XSS() involving safe escaping.

RPG

  • Medium_Severity.png: Resolved a false positive for RPG_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for RPG_High_Risk.Path_Traversal() involving validated paths.

Scala

  • Medium_Severity.png: Resolved a false positive for Scala_High_Risk.SQL_Injection() involving safe parameterized queries.

Swift

  • High_Severity.png: Resolved a false positive for Swift_Critical_Risk.SQL_Injection() involving safe parameter binding.

  • High_Severity.png: Resolved a false positive for Swift_Critical_Risk.Command_Injection() involving safe Process usage.

  • Medium_Severity.png: Resolved a false positive for Swift_High_Risk.XSS() involving safe encoding.

VB6

  • Medium_Severity.png: Resolved a false positive for VB6_High_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for VB6_High_Risk.Path_Traversal() involving validated paths.

Rust

  • High_Severity.png: Resolved a false positive for Rust_Critical_Risk.Command_Injection() involving safe Command usage.

  • High_Severity.png: Resolved a false positive for Rust_Critical_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for Rust_High_Risk.SQL_Injection() involving safe parameterization.

ObjC

  • High_Severity.png: Resolved a false positive for ObjC_Critical_Risk.SQL_Injection() involving safe parameterized queries.

  • Medium_Severity.png: Resolved a false positive for ObjC_High_Risk.XSS() involving safe escaping.

  • Medium_Severity.png: Resolved a false positive for ObjC_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for ObjC_High_Risk.Command_Injection() involving safe NSTask usage.

  • Medium_Severity.png: Resolved a false positive for ObjC_High_Risk.SSRF() involving safe URL validation.

VbNet

  • High_Severity.png: Resolved a false positive for VbNet_Critical_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for VbNet_High_Risk.XSS() involving safe encoding.

  • Medium_Severity.png: Resolved a false positive for VbNet_High_Risk.Path_Traversal() involving validated paths.

Other

  • High_Severity.png: Resolved a false positive for Other_Critical_Risk.SQL_Injection() involving safe parameterization.

  • Medium_Severity.png: Resolved a false positive for Other_High_Risk.Path_Traversal() involving validated paths.

  • Medium_Severity.png: Resolved a false positive for Other_High_Risk.Command_Injection() involving safe argument handling.

  • Medium_Severity.png: Resolved a false positive for Other_High_Risk.XSS() involving safe escaping.