| DISA-6r1 |
Severity | C/C++ Warning Classes |
Java Warning Classes |
C# Warning Classes |
Kotlin Warning Classes |
Python Warning Classes |
| DISA-6r1:V-222396 The application must implement DoD-approved encryption to protect the confidentiality of remote access sessions. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222397 The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222542 The application must only store cryptographic representations of passwords. |
high | |
- |
- |
- |
- |
| DISA-6r1:V-222543 The application must transmit only cryptographically-protected passwords. |
high | |
- |
- |
- |
- |
| DISA-6r1:V-222567 The application must not be vulnerable to race conditions. |
medium |
| closely mapped |
|
| also related |
|
|
- |
- |
- |
- |
| DISA-6r1:V-222570 The application must utilize FIPS-validated cryptographic modules when signing application components. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222571 The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222572 The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222583 The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222589 The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222596 The application must protect the confidentiality and integrity of transmitted information. |
high | |
- |
- |
- |
- |
| DISA-6r1:V-222602 The application must protect from Cross-Site Scripting (XSS) vulnerabilities. |
high | - |
|
|
- |
- |
| DISA-6r1:V-222604 The application must protect from command injection. |
high | |
|
|
- |
- |
| DISA-6r1:V-222606 The application must validate all input. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222607 The application must not be vulnerable to SQL Injection. |
high | |
|
|
- |
- |
| DISA-6r1:V-222608 The application must not be vulnerable to XML-oriented attacks. |
high | - |
|
|
- |
- |
| DISA-6r1:V-222609 The application must not be subject to input handling vulnerabilities. |
high | |
- |
- |
- |
- |
| DISA-6r1:V-222612 The application must not be vulnerable to overflow attacks. |
high |
| closely mapped |
|
| also related |
|
| hierarchy ancestor |
|
|
- |
- |
- |
- |
| DISA-6r1:V-222642 The application must not contain embedded authentication data. |
high | |
- |
- |
- |
- |
| DISA-6r1:V-222656 The application must not be subject to error handling vulnerabilities. |
medium | |
- |
- |
- |
- |
| DISA-6r1:V-222662 Default passwords must be changed. |
high | - |
| also related |
|
| hierarchy ancestor |
|
|
|
- |
- |
| DISA-5r3 |
Severity | C/C++ Warning Classes |
Java Warning Classes |
C# Warning Classes |
Kotlin Warning Classes |
Python Warning Classes |
| DISA-5r3:V-69257 The application must implement DoD-approved encryption to protect the confidentiality of remote access sessions. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-69259 The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-69567 The application must only store cryptographic representations of passwords. |
high | |
- |
- |
- |
- |
| DISA-5r3:V-69569 The application must transmit only cryptographically-protected passwords. |
high | |
- |
- |
- |
- |
| DISA-5r3:V-70185 The application must not be vulnerable to race conditions. |
medium |
| closely mapped |
|
| also related |
|
|
- |
- |
- |
- |
| DISA-5r3:V-70191 The application must utilize FIPS-validated cryptographic modules when signing application components. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70193 The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70195 The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70217 The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70229 The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70245 The application must protect the confidentiality and integrity of transmitted information. |
high | |
- |
- |
- |
- |
| DISA-5r3:V-70257 The application must protect from Cross-Site Scripting (XSS) vulnerabilities. |
high | - |
|
|
- |
- |
| DISA-5r3:V-70261 The application must protect from command injection. |
high | |
|
|
- |
- |
| DISA-5r3:V-70265 The application must validate all input. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70267 The application must not be vulnerable to SQL Injection. |
high | |
|
|
- |
- |
| DISA-5r3:V-70269 The application must not be vulnerable to XML-oriented attacks. |
high | - |
|
|
- |
- |
| DISA-5r3:V-70271 The application must not be subject to input handling vulnerabilities. |
high | |
- |
- |
- |
- |
| DISA-5r3:V-70277 The application must not be vulnerable to overflow attacks. |
high |
| closely mapped |
|
| also related |
|
|
- |
- |
- |
- |
| DISA-5r3:V-70363 The application must not contain embedded authentication data. |
high | |
- |
- |
- |
- |
| DISA-5r3:V-70391 The application must not be subject to error handling vulnerabilities. |
medium | |
- |
- |
- |
- |
| DISA-5r3:V-70403 Default passwords must be changed. |
high | - |
|
|
- |
- |
| DISA-4r3 |
C/C++ Warning Classes |
Java Warning Classes |
C# Warning Classes |
Kotlin Warning Classes |
Python Warning Classes |
| DISA-4r3:V-69257 The application must implement DoD-approved encryption to protect the confidentiality of remote access sessions. |
|
- |
- |
- |
- |
| DISA-4r3:V-69259 The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
|
- |
- |
- |
- |
| DISA-4r3:V-69567 The application must only store cryptographic representations of passwords. |
|
- |
- |
- |
- |
| DISA-4r3:V-69569 The application must transmit only cryptographically-protected passwords. |
|
- |
- |
- |
- |
| DISA-4r3:V-70185 The application must not be vulnerable to race conditions. |
| closely mapped |
|
| also related |
|
|
- |
- |
- |
- |
| DISA-4r3:V-70191 The application must utilize FIPS-validated cryptographic modules when signing application components. |
|
- |
- |
- |
- |
| DISA-4r3:V-70193 The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
|
- |
- |
- |
- |
| DISA-4r3:V-70195 The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
|
- |
- |
- |
- |
| DISA-4r3:V-70217 The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
|
- |
- |
- |
- |
| DISA-4r3:V-70229 The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
|
- |
- |
- |
- |
| DISA-4r3:V-70245 The application must protect the confidentiality and integrity of transmitted information. |
|
- |
- |
- |
- |
| DISA-4r3:V-70257 The application must protect from Cross-Site Scripting (XSS) vulnerabilities. |
- |
|
|
- |
- |
| DISA-4r3:V-70261 The application must protect from command injection. |
|
|
|
- |
- |
| DISA-4r3:V-70265 The application must validate all input. |
|
- |
- |
- |
- |
| DISA-4r3:V-70267 The application must not be vulnerable to SQL Injection. |
|
|
|
- |
- |
| DISA-4r3:V-70269 The application must not be vulnerable to XML-oriented attacks. |
- |
|
|
- |
- |
| DISA-4r3:V-70271 The application must not be subject to input handling vulnerabilities. |
|
- |
- |
- |
- |
| DISA-4r3:V-70277 The application must not be vulnerable to overflow attacks. |
| closely mapped |
|
| also related |
|
|
- |
- |
- |
- |
| DISA-4r3:V-70363 The application must not contain embedded authentication data. |
|
- |
- |
- |
- |
| DISA-4r3:V-70391 The application must not be subject to error handling vulnerabilities. |
|
- |
- |
- |
- |
| DISA-4r3:V-70403 Default passwords must be changed. |
- |
|
|
- |
- |
Mappings for Version 3, release 10 are available for C and C++
warning classes only.
| DISA-3r10 |
C/C++ Warning Classes |
| DISA-3r10:V-6135 The designer will ensure the appropriate cryptography is used to protect stored DoD information if required by the information owner. |
|
| DISA-3r10:V-6136 The designer will ensure data transmitted through a commercial or wireless network is protected using an appropriate form of cryptography. |
|
| DISA-3r10:V-6137 The designer will ensure the application uses the Federal Information Processing Standard (FIPS) 140-2 validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
|
| DISA-3r10:V-6149 The designer will ensure the application does not contain source code that is never invoked during operation, except for software components and libraries from approved third-party products. |
|
| DISA-3r10:V-6156 The designer will ensure the application does not contain embedded authentication data. |
|
| DISA-3r10:V-6157 The designer will ensure the application does not contain invalid URL or path references. |
|
| DISA-3r10:V-6164 The designer will ensure the application validates all input. |
|
| DISA-3r10:V-6165 The designer will ensure the application does not have buffer overflows, use functions known to be vulnerable to buffer overflows, and does not use signed values for memory allocation where permitted by the programming language. |
| closely mapped |
|
| also related |
|
|
| DISA-3r10:V-6166 The designer will ensure the application is not subject to error handling vulnerabilities. |
|
| DISA-3r10:V-16793 The designer will ensure the application properly clears or overwrites all memory blocks used to process sensitive data, if required by the information owner, and clears or overwrites all memory blocks used for classified data. |
|
| DISA-3r10:V-16796 The designer will ensure the application transmits account passwords in an approved encrypted format. |
|
| DISA-3r10:V-16797 The designer will ensure the application stores account passwords in an approved encrypted format. |
|
| DISA-3r10:V-16804 The designer will ensure the application does not rely solely on a resource name to control access to a resource. |
|
| DISA-3r10:V-16807 The designer will ensure the application is not vulnerable to SQL Injection, uses prepared or parameterized statements, does not use concatenation or replacement to build SQL queries, and does not directly access the tables in a database. |
|
| DISA-3r10:V-16808 The designer will ensure the application is not vulnerable to integer arithmetic issues. |
| closely mapped |
|
| also related |
|
|
| DISA-3r10:V-16809 The designer will ensure the application does not contain format string vulnerabilities. |
|
| DISA-3r10:V-16810 The designer will ensure the application does not allow command injection. |
|
| DISA-3r10:V-16815 The designer will ensure the application is not vulnerable to race conditions. |
| closely mapped |
|
| also related |
|
|