C and C++ Binaries


IO.INJ.SQL : SQLインジェクション

要旨

汚染された可能性のあるデータが SQL クエリの構成として使用されています。

プロパティ

クラス名 SQL Injection
日本語クラス名 SQLインジェクション
クラス分類 セキュリティ (security)
ニーモニック IO.INJ.SQL
カテゴリー
MisraC2023 MisraC2023:D.4.14 The validity of values received from external sources shall be checked
Misra2012 Misra2012:D.4.14 The validity of values received from external sources shall be checked
AUTOSARC++14 AUTOSARC++14:A27-0-1 Inputs from independent components shall be validated.
CWE CWE:89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CERT-C CERT-C:STR02-C Sanitize data passed to complex subsystems
DISA-6r1 DISA-6r1:V-222606 The application must validate all input.
  DISA-6r1:V-222607 The application must not be vulnerable to SQL Injection.
  DISA-6r1:V-222609 The application must not be subject to input handling vulnerabilities.
DISA-5r3 DISA-5r3:V-70265 The application must validate all input.
  DISA-5r3:V-70267 The application must not be vulnerable to SQL Injection.
  DISA-5r3:V-70271 The application must not be subject to input handling vulnerabilities.
DISA-4r3 DISA-4r3:V-70265 The application must validate all input.
  DISA-4r3:V-70267 The application must not be vulnerable to SQL Injection.
  DISA-4r3:V-70271 The application must not be subject to input handling vulnerabilities.
DISA-3r10 DISA-3r10:V-6164 The designer will ensure the application validates all input.
  DISA-3r10:V-16807 The designer will ensure the application is not vulnerable to SQL Injection, uses prepared or parameterized statements, does not use concatenation or replacement to build SQL queries, and does not directly access the tables in a database.
OWASP-2017 OWASP-2017:A1 Injection
OWASP-2021 OWASP-2021:A3 Injection
対応言語 C および C++ で利用可能です。
有効/無効設定 このワーニングクラスのチェックはデフォルトで有効になっています。チェックを無効にするにはプロジェクト設定ファイル (configuration file)に以下の WARNING_FILTER ルールを追加してください。
WARNING_FILTER += discard class="SQL Injection"

#include <stdio.h>
#include <sql.h>

RETCODE lookup_by_email (SQLHSTMT hstmt){
    int querylen; 
    SQLCHAR query[256];
    char useremail[128];

    printf("Enter your email address.");
    if (!fgets(useremail, 64, stdin)) return SQL_ERROR;    

    querylen = sprintf(query, 
                       "SELECT * FROM userinfo WHERE email = %s", 
                       useremail);
    return SQLExecDirect(hstmt, query, querylen); /* 'SQL Injection' warning issued here */
}

ワーニングを引き起こす関数

CodeSonar ships with library models that allow it to functions such as libpq PQexec() and Win32 SQLPrepareA() that use one or more of their parameters to construct an SQL query. If one of these functions is called with a tainted value in one of those parameter positions, a warning will be issued.

If you have created a custom library model for some function f() in terms of one of these existing models, calls to f() will also be capable of triggering SQL Injection warnings.

関連のある設定ファイルパラメータ

設定ファイルの以下のパラメータがこのワーニングクラスのチェックに影響します。