• Hi @ksingh880952 (Community Member)​ ,

     

    Veracode Static Analysis reports CWE 99 when we can see that dynamic data from outside the application is injected into a downstream request. We report that for a number or languages and frameworks and it's hard to give a recommendation without knowing more about the technologies used but you can typically think of it very much like CWE 73 File Path injection. A request for a resource is being made (for CWE 73 it's typically a file, for CWE 99 it may be some AEM content or an AWS resource for example). If an attacker is able to influence this request they may be able to access more than intended.

     

    You can find some of the recommended strategies for this CWE here: https://community.veracode.com/s/article/how-do-i-fix-cwe-73-external-control-of-file-name-or-path-in-java .

     

    If you have any other questions, I would recommend you schedule a consultation call to discuss.

    You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.

     

    Thank you,

    Boy Baukema

    Veracode Application Security Consulting

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.