[ { "id": "WVE-2022-0301", "description": "Java network access", "extensions": ["java", "jsp", "jspf"], "keywords": ["java.net.URL ","java.net.URL;"], "score": 3, "level": "A" }, { "id": "WVE-2022-0302", "description": "iframe usage", "extensions": ["java", "jsp", "jspf", "html"], "keywords": ["iframe"], "score": 5, "level": "A" }, { "id": "WVE-2023-0303", "description": "FTP Usage", "extensions": ["java", "jsp", "jspf"], "keywords": ["FTPClient"], "score": 5, "level": "A" }, { "id": "WVE-2023-0304", "description": "Sharepoint usage", "extensions": ["java", "jsp", "jspf"], "keywords": ["SharepointClient"], "score": 5, "level": "A" }, { "id": "WVE-2022-0101", "description": "Privilege escalation using direct database access", "extensions": ["java", "jsp", "jspf"], "keywords": ["java.sql.Connection","java.sql.Driver","java.sql.Statement","java.sql.SQL"], "score": 9, "level": "B" }, { "id": "WVE-2022-0201", "description": "Privilege escalation using POM layer", "extensions": ["java", "jsp", "jspf"], "keywords": ["PersistenceServerHelper.manager."], "score": 7, "level": "B" }, { "id": "WVE-2022-0202", "description": "Privilege escalation using session", "extensions": ["java", "jsp", "jspf"], "keywords": ["SessionServerHelper.manager.setAccessEnforced", "SessionHelper.manager.setAdministrator"], "score": 7, "level": "B" }, { "id": "WVE-2022-0203", "description": "Privilege escalation using wex API", "extensions": ["java", "jsp", "jspf"], "keywords": ["WexAdminSwitcher", "WexContextSwitcher"], "score": 7, "level": "B" }, { "id": "WVE-2022-0204", "description": "Privilege escalation using session", "extensions": ["java", "jsp", "jspf"], "keywords": ["setPrincipal"], "score": 7, "level": "B" }, { "id": "WVE-2022-0401", "description": "Persistent Event", "extensions": ["java", "jsp", "jspf"], "keywords": ["PersistenceManagerEvent"], "score": 9, "level": "B" }, { "id": "WVE-2022-0501", "description": "JSP calls backend, possible XSS, CSRF and access issue", "extensions": [ "jsp", "jspf"], "keywords": ["wex:invoke","WexInvoker.invoke"], "score": 3, "level": "B" }, { "id": "WVE-2023-0502", "description": "File creation", "extensions": [ "java","jsp", "jspf"], "keywords": ["copyInputStreamToFile","FileWriter","FileOutputStream","mkdir"], "score": 6, "level": "B" }, { "id": "WVE-2023-0503", "description": "Use of request parameter - deprecated replaced by WVE-2023-0504, WVE-2023-0505 ", "extensions": [ "java","jsp", "jspf"], "keywords": ["xxxx-getParameter","xxxx-getParameters"], "score": 5, "level": "B" }, { "id": "WVE-2023-0504", "description": "Use of request parameter (XSS risk)", "extensions": [ "java","jsp", "jspf"], "keywords": ["getParameter(","getParameterValues("], "score": 5, "level": "B" }, { "id": "WVE-2023-0505", "description": "Use of request parameter map (XSS risk)", "extensions": [ "java","jsp", "jspf"], "keywords": ["getParameterMap("], "score": 5, "level": "B" }, { "id": "WVE-2023-0506", "description": "Use of output stream (XSS,Path disclosure risk)", "extensions": [ "java","jsp", "jspf"], "keywords": ["getOutputStream(","getWriter("], "score": 6, "level": "B" }, { "id": "WVE-2023-0507", "description": "Use of Windchill temp area", "extensions": [ "java","jsp", "jspf"], "keywords": ["wt.temp"], "score": 5, "level": "B" }, { "id": "WVE-2023-0508", "description": "Use of Java temp area", "extensions": [ "java","jsp", "jspf"], "keywords": ["java.io.tmpdir"], "score": 5, "level": "B" }, { "id": "WVE-2023-0509", "description": "Use of Java temp file", "extensions": [ "java","jsp", "jspf"], "keywords": ["createTempFile("], "score": 5, "level": "B" }, { "id": "WVE-2024-0510", "description": "Use of Feedback that must be sanitized", "extensions": [ "java","jsp", "jspf"], "keywords": ["new FeedbackMessage("], "score": 5, "level": "B" }, { "id": "WVE-2024-0511", "description": "Some operations that consume resources must be rate limited", "extensions": [ "java"], "keywords": ["FormResult doOperation"], "score": 5, "level": "B" }, { "id": "WVE-2022-0402", "description": "Extension Listener", "extensions": ["java", "jsp", "jspf"], "keywords": ["WexWtListener"], "score": 5, "level": "C" }, { "id": "WVE-2022-0403", "description": "Standard Listener", "extensions": ["java", "jsp", "jspf"], "keywords": ["ServiceEventListenerAdapter"], "score": 5, "level": "C" } ]