Medium High
Name Severity Scopes Tags Links
User-controlled data in ServiceCallout High Step Data Validation CWE-233 CWE-20
Use of weak hash algorithms High AssignMessage HMAC JavaScript Secure Configuration CWE-327
Unsafe variable is used to define host High Step Data Validation CWE-20
Unsafe regular expression High Step Data Validation CWE-1333
Unreachable RouteRule Medium Proxy Code Quality CWE-561
Unreachable Flow Medium Target Proxy Code Quality CWE-561
Unreachable FaultRule Medium Target Proxy Code Quality CWE-561
Target URL is tainted by user input High Step Data Validation CWE-22 CWE-233 CWE-918 CWE-20
SpikeArrest policy doesn't use any identifier High SpikeArrest DoS Protection CWE-770
ServiceCallout policy uses default message object as a response Medium ServiceCallout Code Quality CWE-200
ServiceCallout policy uses default message object as a request Medium ServiceCallout Code Quality CWE-200
Request content is tainted by user input High Step Data Validation CWE-20 CWE-116
Proxy doesn't have default flow High Proxy Code Quality Data Validation CWE-20
Private flow variable is written into public one Medium Step Data at Rest CWE-532
Policy sets confidential data in URL parameters High Step Data in Transit CWE-598
Open Redirect High Step Data Validation CWE-601 CWE-20
No TLS protocol specified in connection definition High ServiceCallout MessageLogging Target Data in Transit CWE-327
No SpikeArrest policy is applied Medium Proxy Code Quality DoS Protection CWE-770
MatchesPath is applied to a static parameter Medium Target Proxy Code Quality Data Validation CWE-20
Masked flow variable is written into unmasked one Medium Step Data at Rest CWE-532