Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-278

console: sql injection protection not working properly

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Medium Medium
    • Amsterdam Release
    • Amsterdam Release
    • None

      SimpleBindings logic have issues on ONAP for SQL injection protection

       

      Found Problems:

      • There is a missing colon before named parameter in POLICY-SDK-APP/src/main/java/org/onap/policy/admin/PolicyManagerServlet.java
      • Hibernate setParameter() mistakes long data type as int and tries to cast, then fails and throws exception

            cr056n cr056n
            jhh jhh
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: