SPatnaik392914 (Community Member) asked a question.

What is Attack Vector: UNDERPERMISSION

Description: This application calls the UNDERPERMISSION() API, which requires the following permission(s) that are not specified in Apex code: . These calls will not be executed. Depending on implementation, this condition may result in an error message, or the code will fail silently. Underpermission conditions are not exploitable flaws, but they may indicate the presence of unexpected code (e.g. an advertising library attempting to leak the user's GPS location).

Remediation: This message is purely informational and does not represent a flaw in the code. Therefore, no remediation is necessary.


  • User16877954737335246824 (Veracode, Inc.)

    Hi,

     

    Could you please let me know what assistance is needed from the Veracode end.

     

    Regards,

    Pranita

    Veracode Inc.

    Expand Post
  • SPatnaik392914 (Community Member)

    I want to understand the issue and how it can be improved?

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.