How to resolve veracode scan sql conection error(cwe 15).
Loading
How to resolve veracode scan sql conection error(cwe 15).
Know the answer? Post it — somebody with the same question will find it here.
Sign in to answer this question
It is the same account you read, post and publish with — and you will come straight back to this page.
satish maddiliPosted Oct 31, 2023, 6:49 AM
Hi Sachin,
I am reading connection string from web.config
private readonly string _connectionString = string.Empty;
private readonly int _sqlTimeout = 30;
public AdoUtility(string connectionString, int sqlTimeout)
{
this._connectionString = connectionString;
this._sqlTimeout = sqlTimeout;
}
using (SqlConnection cn = new SqlConnection())
{
cn.ConnectionString = _connectionString;
cn.Open();
cn.Close();
}
using (SqlConnection cn = new SqlConnection())
{
cn.ConnectionString = _connectionString;
above lines gettng error
Sachin SinghPosted Oct 4, 2023, 6:16 AM
I guess you are preparing the Connection String using the server name and db name as input, and the scan is considering it as a threat. Try to avoid preparing connection strings with user input and keep it in web config or app config and read it based on the user login, you can create a connection factory class etc for that.