| Connection to the system is not encrypted | Critical | ServiceCallout
                MessageLogging
                Target | Data in Transit | CWE-319 | 
                                
                                    | Lack of certificate validation | Critical | ServiceCallout
                MessageLogging
                Target | Data in Transit | CWE-295 | 
                                
                                    | AssignMessage request parameters pollution | High | AssignMessage | Data Validation | CWE-20 | 
                                
                                    | Flow accepts confidential data as URL parameters | High | Flow
                PreFlow | Data in Transit | CWE-598 | 
                                
                                    | JSONThreatProtection policy is not applied to a request body with JSON type | High | Flow | Data Validation | CWE-502
                                            CWE-20 | 
                                
                                    | No TLS protocol specified in connection definition | High | ServiceCallout
                MessageLogging
                Target | Data in Transit | CWE-327 | 
                                
                                    | Use of weak hash algorithms | High | AssignMessage
                HMAC
                JavaScript | Secure Configuration | CWE-327 | 
                                
                                    | Condition has undefined variables | Medium | Step
                RouteRule
                Flow | Code Quality | CWE-570
                                            CWE-571 | 
                                
                                    | Flow accepts requests with any method | Medium | Flow | Data Validation | CWE-749 | 
                                
                                    | Flow doesn't limit HTTP methods correctly | Medium | Flow | Data Validation | CWE-749 | 
                                
                                    | Lack of DefaultFaultRule | Medium | Target
                Proxy | Error Handling | CWE-390 | 
                                
                                    | MatchesPath is applied to a static parameter | Medium | Target
                Proxy | Code Quality
                Data Validation | CWE-20 | 
                                
                                    | Unreachable FaultRule | Medium | Target
                Proxy | Code Quality | CWE-561 | 
                                
                                    | Unreachable Flow | Medium | Target
                Proxy | Code Quality | CWE-561 | 
                                
                                    | Overcomplicated or malformed condition | Low | Step
                RouteRule
                Flow | Code Quality | CWE-570
                                            CWE-571 |