GSC - Demo - Testfire Security Report PDF
GSC - Demo - Testfire Security Report PDF
GSC - Demo - Testfire Security Report PDF
Security Report
This report was created by IBM Security AppScan Standard 9.0.3.2, Rules: 3488
Scan started: 3/9/2015 10:59:00 AM
Table of Contents
Introduction
General Information
Login Settings
Summary
Issue Types
Vulnerable URLs
Fix Recommendations
Security Risks
Causes
WASC Threat Classification
11/05/2016
Introduction
This report contains the results of a web application security scan performed by IBM Security AppScan Standard.
High severity issues:
3
6
General Information
Scan file name:
GSC_demo.testfire
Scan started:
3/9/2015 10:59:00 AM
Test policy:
Web Services(Modified)
Host
demo.testfire.net
IIS
Login Settings
Login method:
Recorded login
Concurrent logins:
Enabled
JavaScript execution:
Disabled
In-session detection:
Enabled
In-session pattern:
Tracked or session ID cookies:
Tracked or session ID parameters:
Login sequence:
11/05/2016
Summary
Issue Types
TOC
Issue Type
Number of Issues
H SQL Injection
I Application Error
Vulnerable URLs
TOC
URL
Number of Issues
H https://demo.testfire.net/transfer/transfer.asmx
Fix Recommendations
12
TOC
Remediation Task
Number of Issues
L Verify that parameter values are in their expected ranges and types.
Do not output debugging error messages and exceptions
Security Risks
TOC
Risk
Number of Issues
11/05/2016
Causes
TOC
Cause
Number of Issues
I No validation was done in order to make sure that user input matches 6
the data type expected
TOC
Threat
Number of Issues
Information Leakage
SQL Injection
11/05/2016
Issue 1 of 3
TOC
TOC
SQL Injection
Severity:
High
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails (Parameter)
Risk:
Causes:
Fix:
Issue 2 of 3
11/05/2016
TOC
SQL Injection
Severity:
High
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->debitAccount (Parameter)
Risk:
Causes:
Fix:
Issue 3 of 3
TOC
SQL Injection
Severity:
High
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->creditAccount (Parameter)
Risk:
Causes:
Fix:
11/05/2016
Issue 1 of 3
TOC
TOC
Low
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails (Global)
Risk:
Causes:
Fix:
Issue 2 of 3
TOC
Low
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->debitAccount (Global)
Risk:
Causes:
Fix:
11/05/2016
Issue 3 of 3
TOC
Low
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->creditAccount (Global)
Risk:
Causes:
Fix:
11/05/2016
Application Error
Issue 1 of 6
TOC
TOC
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->creditAccount (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
Issue 2 of 6
TOC
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
11/05/2016
Issue 3 of 6
TOC
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
Issue 4 of 6
TOC
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->transferDate (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
Issue 5 of 6
11/05/2016
TOC
10
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->transferAmount (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
Issue 6 of 6
TOC
Application Error
Severity:
Informational
https://demo.testfire.net/transfer/transfer.asmx
Entity:
->Envelope->Body->TransferBalance->transDetails->debitAccount (Parameter)
Risk:
Causes:
Fix:
Verify that parameter values are in their expected ranges and types. Do not output debugging error
messages and exceptions
Reasoning: The application has responded with an error message, indicating an undefined state that
may expose sensitive information.
11/05/2016
11