IBM Support

PH09197: ANGULARJS LOCAL STORAGE VULNERABILITY TYPE IS INCORRECT

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • AngularJS Local Storage vulnerability type is "Required", e.g.
    when scanning statement
    "return localStorage.getItem('x');"
    
    Expected behavior:
    AngularJS Local Storage vulnerability type should be "Cross Site
    Scripting"
    

Local fix

  • Any workaround:
    None
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Any user who try to generate a report off of their           *
    * JavaScript scan results may notice this issue.               *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * When a report generated off of results from an AngularJS     *
    * code scan, the vulnerability type of a finding is            *
    * incorrectly shown as  "Required" whereas it should have been *
    * "Validation.Required"                                        *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Upgrade AppScan Source for Analysis to version 9.0.3.12 to   *
    * get the fix for this reported issue.                         *
    ****************************************************************
    

Problem conclusion

  • Upgrade product to version 9.0.3.12
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH09197

  • Reported component name

    SEC APPSCAN SRC

  • Reported component ID

    5724Z3400

  • Reported release

    903

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-02-28

  • Closed date

    2019-03-27

  • Last modified date

    2019-03-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SEC APPSCAN SRC

  • Fixed component ID

    5724Z3400

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSS9LM","label":"IBM Security AppScan Source for Automation"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"903","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
27 March 2019