
...
Tool | Version | Checker | Description | ||||||
---|---|---|---|---|---|---|---|---|---|
The Checker Framework |
| Tainting Checker | Trust and security errors (see Chapter 8) | ||||||
Fortify | 1.0 | Missing_XML_Validation | Implemented | ||||||
Klocwork |
| SV.XXE.DBF | |||||||
SonarQube |
|
Bibliography
A Guide to Building Secure Web Applications and Web Services | |
IDS17-J. Prevent XML External Entity Attacks LiveLesson | |
[W3C 2008] | Section 4.4.3, "Included If Validating" |
...