Step Target
Name Scopes Tags Links
High
User-controlled data in ServiceCallout Step Data Validation CWE-233 CWE-20
Unsafe variable is used to define host Step Data Validation CWE-20
Unsafe regular expression Step Data Validation CWE-1333
Target URL is tainted by user input Step Data Validation CWE-22 CWE-233 CWE-918 CWE-20
Request content is tainted by user input Step Data Validation CWE-20 CWE-116
Policy sets confidential data in URL parameters Step Data in Transit CWE-598
Open Redirect Step Data Validation CWE-601 CWE-20
No TLS protocol specified in connection definition ServiceCallout MessageLogging Target Data in Transit CWE-327
Info
Unused flow variables Step Code Quality CWE-563
Medium
Unreachable Flow Target Proxy Code Quality CWE-561
Unreachable FaultRule Target Proxy Code Quality CWE-561
Private flow variable is written into public one Step Data at Rest CWE-532
MatchesPath is applied to a static parameter Target Proxy Code Quality Data Validation CWE-20
Masked flow variable is written into unmasked one Step Data at Rest CWE-532
Low
Step operates undefined flow variables Step Code Quality CWE-457
Policy errors are not caught Step Error Handling CWE-390
Overcomplicated or malformed condition Step RouteRule Flow Code Quality CWE-570 CWE-571
Critical
Sensitive information is in the source code Step Data at Rest CWE-256 CWE-312
Request content is stringified Step Data Validation DoS Protection CWE-20
Lack of certificate validation ServiceCallout MessageLogging Target Data in Transit CWE-295