Skip to main content
assistive.skiplink.to.breadcrumbs
assistive.skiplink.to.header.menu
assistive.skiplink.to.action.menu
assistive.skiplink.to.quick.search
Log in
Confluence
Spaces
Hit enter to search
Help
Online Help
Keyboard Shortcuts
Feed Builder
What’s new
Available Gadgets
About Confluence
Log in
SEI CERT Oracle Coding Standard for Java
Pages
Boards
Space shortcuts
Dashboard
Secure Coding Home
Android
C
C++
Java
Perl
Page tree
Browse pages
Configure
Space tools
View Page
A
t
tachments (0)
Page History
Page Information
View in Hierarchy
View Source
Export to PDF
Export to Word
Pages
…
SEI CERT Oracle Coding Standard for Java
3 Recommendations
Rec. 00. Input Validation and Data Sanitization (IDS)
IDS53-J. Prevent XPath Injection
Page Information
Title:
IDS53-J. Prevent XPath Injection
Author:
John Truelove
Apr 02, 2009
Last Changed by:
Michal Rozenau
Jan 10, 2023
Tiny Link:
(useful for email)
https://wiki.sei.cmu.edu/confluence/x/cDZGBQ
Export As:
Word
·
PDF
Incoming Links
Android (1)
Page:
Applicability Test
Hierarchy
Parent Page
Page:
Rec. 00. Input Validation and Data Sanitization (IDS)
Labels
Global Labels (11)
security
review-dm
review-dfs
reviewed-fwl
out-of-scope
ids
android-applicable
review-rcs
maybe-normative
recommendation
1security
Recent Changes
Time
Editor
Jan 10, 2023 06:21
Michal Rozenau
View Changes
Parasoft Jtest 2022.2
Nov 16, 2017 14:43
Will Snavely
View Changes
Oct 05, 2016 16:36
David Svoboda
View Changes
AD TCF
Apr 07, 2015 12:01
Will Snavely
View Changes
Mar 30, 2015 03:51
Will Snavely
View Page History
Outgoing Links
External Links (8)
www.owasp.org/index.php/XPath_Injection_Testing_AoC
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
java.sun.com/developer/technicalArticles/xml/jaxp1-3/index.…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
AA. References#Oracle 11b
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
www.ibm.com/developerworks/xml/library/x-xpathinjection.htm…
https://www.securecoding.cert.org/confluence/display/java/I…
SEI CERT Oracle Coding Standard for Java (8)
Page:
MSC62-J. Store passwords using a hash function
Page:
Java Coding Guidelines
Page:
IDS52-J. Prevent code injection
Page:
The Checker Framework
Page:
Parasoft
Page:
The Checker Framework_V
Page:
Parasoft_V
Page:
Rec. AA. References
Overview
Content Tools
{"serverDuration": 72, "requestCorrelationId": "2bef618fac04fab3"}