
ABS737838 (Community Member) asked a question.
ID 89)(1 flaw)
Hi, the dynamic scan on my application raised a SQL Injection vulnerability pointing to the attached file builder_all.min.js.
My application is running on Oracle APEX and this file makes the APEX page designer work with Microsoft Explorer, this is, if I delete the file is not possible work with APEX in Explorer or Edge.
APEX is runing on Apache Tomcat.
Any idea where can be the part of the code that is causing the problem?
And in that case, how can it be solved?
Thanks!
.png)
We will need more specific details to help investigate what part is triggering an SQL injection flaw.
I would recommend you schedule a consultation call to discuss.
You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.
Thank you,
Boy Baukema