SV-222606r508029_rule
V-222606
SRG-APP-000251
APSC-DV-002530
CAT II
10
Design and configure the application to validate input prior to executing commands.
Review the application documentation, the code review reports and the vulnerability assessment scan results from automated vulnerability assessment tools.
Verify scan configuration settings include input validation and fuzzing tests.
Test data entry fields on all pages/screens of the application.
Procedures on testing input are relevant to the architecture of the application.
A reference on input validation testing is included at the OWASP website. The site includes testing procedures for input validation that affect many different technologies.
Identify the relevant testing procedures based upon the application architecture and components being tested.
https://www.owasp.org/index.php/Testing_for_Input_Validation
If test results include input validation errors, or if no test results exist, this is a finding.
V-222606
False
APSC-DV-002530
Review the application documentation, the code review reports and the vulnerability assessment scan results from automated vulnerability assessment tools.
Verify scan configuration settings include input validation and fuzzing tests.
Test data entry fields on all pages/screens of the application.
Procedures on testing input are relevant to the architecture of the application.
A reference on input validation testing is included at the OWASP website. The site includes testing procedures for input validation that affect many different technologies.
Identify the relevant testing procedures based upon the application architecture and components being tested.
https://www.owasp.org/index.php/Testing_for_Input_Validation
If test results include input validation errors, or if no test results exist, this is a finding.
M
4093