ServiceCallout Proxy
Name Scopes Tags Links
Medium
Unreachable RouteRule Proxy Code Quality CWE-561
Unreachable Flow Target Proxy Code Quality CWE-561
Unreachable FaultRule Target Proxy Code Quality CWE-561
ServiceCallout policy uses default message object as a response ServiceCallout Code Quality CWE-200
ServiceCallout policy uses default message object as a request ServiceCallout Code Quality CWE-200
No SpikeArrest policy is applied Proxy Code Quality DoS Protection CWE-770
MatchesPath is applied to a static parameter Target Proxy Code Quality Data Validation CWE-20
Lack of DefaultFaultRule Target Proxy Error Handling CWE-390
Info
Resource is not linked to a policy Proxy Code Quality CWE-561
Policy is not linked to step Proxy Code Quality CWE-561
Missing API versioning Proxy Secure Configuration CWE-710
High
Proxy doesn't have default flow Proxy Code Quality Data Validation CWE-20
No TLS protocol specified in connection definition ServiceCallout MessageLogging Target Data in Transit CWE-327
Authorization header is not removed before the request is sent to target system Proxy Data in Transit CWE-201
API Key is not removed before the request is sent to target system Proxy Data in Transit CWE-201
Low
No mask configuration for the proxy Proxy Code Quality
Missing security headers Proxy Secure Configuration CWE-523
Critical
Lack of certificate validation ServiceCallout MessageLogging Target Data in Transit CWE-295
Connection to the system is not encrypted ServiceCallout MessageLogging Target Data in Transit CWE-319