Details

    • Type: Language-Specification
    • Status: Active
    • Resolution: Unresolved
    • Labels:
      None
    • Impact:
      Unknown 'null' severity
    • Likelihood:
      Unknown 'null' severity

      Description

      Sensitive Code Example

      MOVE "admin" TO UID.
      MOVE "letMeIn" TO PWD.
      EXEC SQL
        CONNECT :UID  *> Sensitive
        IDENTIFIED BY :PWD  *> Sensitive
        AT :MYCONN
        USING :MYSERVER
      END-EXEC.
      

      Compliant Solution

      DISPLAY env-name-pwd UPON ENVIRONMENT-NAME
      ACCEPT env-val-pwd FROM ENVIRONMENT-VALUE *> Compliant
      
      DISPLAY env-name-uid UPON ENVIRONMENT-NAME
      ACCEPT env-val-uid FROM ENVIRONMENT-VALUE *> Compliant
      
      EXEC SQL
        CONNECT :env-name-uid
        IDENTIFIED BY :env-val-pwd
        AT :MYCONN
        USING :MYSERVER
      END-EXEC.
      

        Attachments

          Activity

            People

            Assignee:
            Unassigned Unassigned
            Reporter:
            ann.campbell.2 Ann Campbell
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated: