Status/Resolution/Reason: Closed/Fixed/
Reporter/Name(from Bugbase): Peter Freitag / Peter Freitag (Peter Freitag)
Created: 03/18/2016
Components: Security Code Analyzer
Versions: 2016
Failure Type: Enhancement Request
Found In Build/Fixed In Build: Beta2_v31 / (in b
Priority/Frequency: Minor / Some users will encounter
Locale/System: English / Win All
Vote Count: 0
Problem Description:
When you have a server setup with secure profile and try to use the security analyzer with it, the security analyzer fails silently. The request to the CF server was sent by builder but results in a 404.
Steps to Reproduce:
I installed Raijin server using secure profile, then installed Blizzard on the same serevr and did not check the box to install a builtin ColdFusion server with Blizzard.
In Blizzard I added a local server mapping pointing to my existing Raijin server. I then right clicked on a file with an obvious SQL injection vulnerability.
No errors are reported and the security analyzer reports 0 issues.
Actual Result:
When I run security analyzer nothing happens no error is reported and the user may think that there are no security issues in their code.
Expected Result:
Expect an error to say security analyzer is not enabled or available on your ColdFusion server.
Any Workarounds:
n/a
----------------------------- Additional Watson Details -----------------------------
Watson Bug ID: 4130071
External Customer Info:
External Company: Foundeo Inc.
External Customer Name: Peter Freitag
External Customer Email: PETE@FOUNDEO.COM
External Test Config:
Attachments:
Comments: