Skip to content

CX Hardcoded_password_in_Connection_String @ root/init.jsp [master] #45

@CxYair

Description

@CxYair

Hardcoded_password_in_Connection_String issue exists @ root/init.jsp in branch master

The application contains hardcoded connection details, """", at line 67 of root\init.jsp. This connection string contains a hardcoded password, which is used in DriverManager.getConnection at line 67 of root\init.jsp to connect to a database server with getConnection. This can expose the database password, and impede proper password management.

Severity: Medium

CWE:547

Checkmarx

Training
Recommended Fix

Lines: 67


Code (Line #67):

    		c = DriverManager.getConnection("jdbc:hsqldb:mem:SQL", "sa", "");

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions