Ajaykittur1981 (Community Member) asked a question.

Static analysis of dfc.jar and rapi_documentum.jar reports a very high CWE 114 vulnerability but this is not reported when these jars are scanned independently

I have a very high vulnerability reported when I scan dfc.jar and rapi_documentum.jar  togther, but same is not reported independently so the vendor is not sure if this needs to be fixed or is a false positive


  • Hi @Ajaykittur1981 (Community Member)​ ,

     

    Veracode Static Analysis does not scan 'jar' files individually, but together in modules.

    We recommend you provide us with the entire application, a good rule of thumb is that it's better to give us too much, than too little. If you do not provide us with the entire application we may not see something being used and may not analyze that part.

     

    I would recommend you schedule a consultation call to discuss.

    You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.

     

    Thank you,

    Boy Baukema

    Expand Post
  • Ajaykittur1981 (Community Member)

    Requested a call to be scheduled using case 00583806

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.