• Hi @ZTongkai339917 (Community Member)​ ,

     

    We do not recommend you attempt to create your own vulnerabilities as these frequently do not represent real risk to the application or organization and will be ignored by Veracode Static Analysis as it is tuned for a high true positive rate.

    Instead we recommend uploading a production application and reviewing the results for this application.

     

    Veracode Static Analysis results output cannot be configured and supports many different flaw categories, you can find an overview here: https://help.veracode.com/go/c_review_cwe . Many but not all will be applicable to COBOL, some examples are CWE 73 External Control of File, CWE 78 OS Command Injection, CWE 80 Basic XSS, CWE 89 SQL Injection, etc.

     

    The Policy configured by your organization controls which flaws must be fixed, you can find more on which policy is configured and it's requirements in the Veracode Platform, more information here: https://help.veracode.com/go/policy_control_report

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.