Direct links to fixes
APAR status
Closed as program error.
Error description
AngularJS Local Storage vulnerability type is "Required", e.g. when scanning statement "return localStorage.getItem('x');" Expected behavior: AngularJS Local Storage vulnerability type should be "Cross Site Scripting"
Local fix
Any workaround: None
Problem summary
**************************************************************** * USERS AFFECTED: * * Any user who try to generate a report off of their * * JavaScript scan results may notice this issue. * **************************************************************** * PROBLEM DESCRIPTION: * * When a report generated off of results from an AngularJS * * code scan, the vulnerability type of a finding is * * incorrectly shown as "Required" whereas it should have been * * "Validation.Required" * **************************************************************** * RECOMMENDATION: * * Upgrade AppScan Source for Analysis to version 9.0.3.12 to * * get the fix for this reported issue. * ****************************************************************
Problem conclusion
Upgrade product to version 9.0.3.12
Temporary fix
Comments
APAR Information
APAR number
PH09197
Reported component name
SEC APPSCAN SRC
Reported component ID
5724Z3400
Reported release
903
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-02-28
Closed date
2019-03-27
Last modified date
2019-03-27
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SEC APPSCAN SRC
Fixed component ID
5724Z3400
Applicable component levels
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSS9LM","label":"IBM Security AppScan Source for Automation"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"903","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]
Document Information
Modified date:
27 March 2019