...
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Checker Framework |
| Tainting Checker | Trust and security errors (see Chapter 8) | ||||||
| Fortify | 1.0 | Missing_XML_Validation | Implemented | ||||||
| Klocwork |
| SV.XXE.DBF | |||||||
| SonarQube |
|
Bibliography
A Guide to Building Secure Web Applications and Web Services | |
IDS17-J. Prevent XML External Entity Attacks LiveLesson | |
| [W3C 2008] | Section 4.4.3, "Included If Validating" |
...