Vishal_Chugh

Absent Member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2014-12-04
06:09
4892 views
Fortify on Oracle codebase
Hi ,
1) HP Fortify SCA (6.10) , doesn't recognize/scan any other extentions ( .pkg , .syn, .trig etc) . It works only on .sql files . That too doesnt report any errors/issues . What all configuraitons steps are required to make other extensions work ? ( Though introducing com.fortify.sca.fileextensions.pkg = PLSQL in fortify-sca.properties dint help , it still remains unrecognized)
2) Introducing SQL-injeciton code ( https://docs.oracle.com/cd/E38689_01/pt853pbr0/eng/pt/tpcd/task_PreventingSQLInjection-0749b7.html ) for testing purpose , also dint help. It doesnt catch this problem as well. It still reports zero errors.
Can someone please advise.
0 Replies