SShaik206211 (Community Member) asked a question.

Veracode static scan does not detect web filter

Hi Team,

we have a java web application which uses a ESAPI based filter (web filter) which is used to sanitize the httpservletrequest​ and httpservletresponse. we observed that this is not considered as remidiation by veracode and it still highlights request.getParameter() or request.getHeader() calls as possible XSS vulnerability.

can you pls let me ​know what can be done to let this filter be considered by scan.

NOTE: the filter has appropriate ESAPI ​based validations and works fine to sanitize the request.


  • Hello @SShaik206211 (Community Member)​ ,

     

    Thank you for reaching out to the Community.

     

    With this issue, I would recommend opening a support ticket. You can open a support ticket within the Community. Simply click on your profile on the top right side of the screen and select "Contact Support." Or click on the link below.

     

    https://community.veracode.com/s/contact-support

     

    Best regards,

    Steven

    Veracode Support Engineer

    Expand Post

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.