You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
As per NVD description , these CVE-2009-2704 and CVE-2009-2705 should be valid if we have combination of cpe:2.3:a:sun:j2ee:::::::: and cpe:2.3:a:broadcom:siteminder:::::::: in scanned project. However, the CVE-2009-2704 and CVE-2009-2705 is getting reported even if we have only one of the matching CPE (cpe:2.3:a:sun:j2ee::::::::) related jar
Version of dependency-check used
The problem occurs using version 8.2.1 of the CLI.
To Reproduce
Steps to reproduce the behavior:
Download any jar named *j2ee.jar and run the OWASP DC CLI - 8.2.1.
CVE-2009-2705 and CVE-2009-2704 configuration having AND condition (multiple CPEs assigned), but with one CPE "cpe:2.3:a:sun:j2ee::::::::" also artifact is listing these CVE's.
The text was updated successfully, but these errors were encountered:
Describe the bug
As per NVD description , these CVE-2009-2704 and CVE-2009-2705 should be valid if we have combination of cpe:2.3:a:sun:j2ee:::::::: and cpe:2.3:a:broadcom:siteminder:::::::: in scanned project. However, the CVE-2009-2704 and CVE-2009-2705 is getting reported even if we have only one of the matching CPE (cpe:2.3:a:sun:j2ee::::::::) related jar
Version of dependency-check used
The problem occurs using version 8.2.1 of the CLI.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
The text was updated successfully, but these errors were encountered: