> For the complete documentation index, see [llms.txt](https://docs.sonarsource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sonarsource.com/sonarqube-server/user-guide/viewing-reports/security-reports.md).

# Security reports

*Security reports are available starting in* [*Enterprise Edition*](https://www.sonarsource.com/plans-and-pricing/enterprise/)*.*

## What do security reports show? <a href="#what-security-reports-show" id="what-security-reports-show"></a>

Security reports quickly give you the big picture of your project, application or portfolio's security. They let you to know where you stand compared to the most common security mistakes made in the past:

* [OWASP Top 10](https://owasp.org/Top10/) (versions 2025, 2021, 2017)

<details>

<summary>OWASP Top 10 security standards covered by Sonar for version 2025</summary>

<table><thead><tr><th width="207.765625">Category</th><th width="87.17962646484375">Python</th><th width="92.93603515625">JS/TS</th><th width="78.802490234375">Java</th><th width="78.2628173828125">C#</th><th width="81.49072265625">C/C++</th><th width="80.1341552734375">PHP</th><th width="86.203125">Kotlin</th><th>Go</th></tr></thead><tbody><tr><td>A01:Broken Access Control</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A02: Security Misconfiguration</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A03: Software Supply Chain Failures</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A04: Cryptographic Failures</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A05: Injection</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A06: Insecure design</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A07: Authentication Failures</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A08: Software and Data Integrity Failures</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>A09: Logging and Alerting Failures</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>A10: Mishandling of Exceptional Conditions</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [OWASP Mobile Top 10 2024](https://owasp.org/www-project-mobile-top-10/)

<details>

<summary>OWASP Mobile Top 10 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="206.4246826171875">Standard</th><th>Java</th><th>Kotlin</th><th>Dart</th><th>Swift</th></tr></thead><tbody><tr><td>M1: Improper Credential Usage</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M2: Inadequate Supply Chain Security</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M3: Insecure Authentication/Authorization</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M4: Insufficient Input/Output Validation</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M5: Insecure Communication</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M6: Inadequate Privacy Controls</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M7: Insufficient Binary Protections</td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td></td><td></td></tr><tr><td>M8: Security Misconfiguration</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>M9: Insecure Data Storage</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td></td></tr><tr><td>M10: Insufficient Cryptography</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr></tbody></table>

</details>

* [CWE Top 25](https://cwe.mitre.org/top25/archive/2024/2024_cwe_top25.html) (versions 2024, 2023, 2022, and 2021)

<details>

<summary>CWE Top 25 security standards covered by Sonar for version 2024</summary>

<table><thead><tr><th width="210.5675048828125">Category</th><th width="83.29473876953125">Python</th><th width="83.7493896484375">JS/TS</th><th width="86.885009765625">Java</th><th width="71.547607421875">C#</th><th width="82.7052001953125">C/C++</th><th width="78.1668701171875">PHP</th><th>Kotlin</th></tr></thead><tbody><tr><td>CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-787 Out-of-bounds Write</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-352 Cross-Site Request Forgery (CSRF)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-125 Out-of-bounds Read</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-416 Use After Free</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-862 Missing Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-434 Unrestricted Upload of File with Dangerous Type</td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-94 Improper Control of Generation of Code (‘Code Injection’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-20 Improper Input Validation</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-77 Improper Neutralization of Special Elements used in a Command (‘Command Injection’)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td></tr><tr><td>CWE-287 Improper Authentication</td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-269 Improper Privilege Management</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-502 Deserialization of Untrusted Data</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-863 Incorrect Authorization</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr><tr><td>CWE-918 Server-Side Request Forgery (SSRF)</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</td><td><br></td><td><br></td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-476 NULL Pointer Dereference</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-798 Use of Hard-coded Credentials</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-190 Integer Overflow or Wraparound</td><td><br></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><br></td></tr><tr><td>CWE-400 Uncontrolled Resource Consumption</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><br></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>CWE-306 Missing Authentication for Critical Function</td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td><td><br></td></tr></tbody></table>

</details>

* [EU Cyber Resilience Act](https://docs.sonarsource.com/cyber-resilience-act)

<details>

<summary>EU Cyber Resilience Act security standards covered by Sonar security features</summary>

<table><thead><tr><th width="420">Requirement</th><th width="140">Security</th><th width="140">Security Hotspots</th></tr></thead><tbody><tr><td>Part I - Cybersecurity requirements relating to the properties of products with digital elements</td><td><img src="/files/6BN8TQvqxdmjCrPCOTpA" alt="Partial coverage"> (partial)</td><td><img src="/files/6BN8TQvqxdmjCrPCOTpA" alt="Partial coverage"></td></tr><tr><td>1.1 Risk-Based Security Standards for Digital Products</td><td></td><td></td></tr><tr><td>1.2 Security Obligations Derived from Risk Assessments</td><td><img src="/files/6BN8TQvqxdmjCrPCOTpA" alt="Partial coverage"></td><td><img src="/files/6BN8TQvqxdmjCrPCOTpA" alt="Partial coverage"></td></tr><tr><td>1.2.a be made available on the market without known exploitable vulnerabilities</td><td></td><td></td></tr><tr><td>1.2.b be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>1.2.c ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them</td><td></td><td></td></tr><tr><td>1.2.d ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>1.2.e protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>1.2.f protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>1.2.g process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)</td><td></td><td></td></tr><tr><td>1.2.h protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks</td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td><td><img src="/files/ZiBj9zoh19XZAtcFGn2D" alt="Checkmark icon"></td></tr><tr><td>1.2.i minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks</td><td></td><td></td></tr><tr><td>1.2.j be designed, developed and produced to limit attack surfaces, including external interfaces</td><td></td><td></td></tr><tr><td>1.2.k be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques</td><td></td><td></td></tr><tr><td>1.2.l provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user</td><td></td><td></td></tr><tr><td>1.2.m provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner</td><td></td><td></td></tr><tr><td>Part II - Vulnerability handling requirements</td><td></td><td></td></tr><tr><td>2.1 identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products</td><td></td><td></td></tr><tr><td>2.2 in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates</td><td></td><td></td></tr><tr><td>2.3 apply effective and regular tests and reviews of the security of the product with digital elements</td><td></td><td></td></tr><tr><td>2.4 once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch</td><td></td><td></td></tr><tr><td>2.5 put in place and enforce a policy on coordinated vulnerability disclosure</td><td></td><td></td></tr><tr><td>2.6 take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements</td><td></td><td></td></tr><tr><td>2.7 provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner</td><td></td><td></td></tr><tr><td>2.8 ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken</td><td></td><td></td></tr></tbody></table>

</details>

* [CASA](https://appdefensealliance.dev/casa)
* [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) (version 4.0 level 1, 2, 3)
* [PCI DSS](https://www.pcisecuritystandards.org/) (versions 4.0 and 3.2.1)
* [STIG ASD](https://www.cyber.mil/stigs/) (version 6 and 5)

They represent the bare minimum compliance for anyone putting in place a secure development lifecycle.

Depending on the configuration of your SonarQube Server instance, security reports are generated with metrics either from [Standard Experience](/sonarqube-server/instance-administration/analysis-functions/instance-mode/standard-experience.md) or [MQR mode](/sonarqube-server/instance-administration/analysis-functions/instance-mode/mqr-mode.md).

### Software Composition Analysis (SCA) in security reports

If you have [SonarQube Advanced Security](https://www.sonarsource.com/solutions/security/), the reports include Software Composition Analysis (SCA) data in a **Dependency Risk** column for project, application and portfolio-level reports in both the SonarQube Server UI and exported PDFs. See [Advanced Security](/sonarqube-server/advanced-security.md) for more details.

## What are the differences among the security issues? <a href="#the-difference-between-a-security-hotspot-and-a-vulnerability" id="the-difference-between-a-security-hotspot-and-a-vulnerability"></a>

> **Note:** To simplify the classification of findings, we are gradually transitioning security hotspots to vulnerabilities. As a result, rules that previously raised security hotspots will start raising vulnerabilities (in Standard Experience) or security issues (in MQR Mode).

Security Hotspots and Security Vulnerabilities (in Standard Experience) or Security issues (in MQR Mode) differ in that:

* Security Hotspot is a security-sensitive piece of code that is highlighted but doesn’t necessarily impact the overall application security. It’s up to the developer to review the code and determine whether or not a fix is needed to secure it.
* Security Vulnerability (in Standard Experience) or Security (in MQR Mode) is a problem that impacts the application’s security and needs to be fixed immediately.

For more details, see the [Managing Security Hotspots](/sonarqube-server/user-guide/security-hotspots.md) page.

## Why don’t I see any security issues? <a href="#i-do-not-see-vulnerabilities-or-security-hotspots" id="i-do-not-see-vulnerabilities-or-security-hotspots"></a>

A rating is unavailable and displayed as a dash (-) for Security Vulnerabilities (in Standard Experience), Security issues (in MQR Mode), or Security Hotspots for the following reasons:

* Your code has been written without using any security-sensitive API.
* Security Vulnerability (in Standard Experience), Security (in MQR Mode), or Security Hotspot rules are available but not activated in your quality profile, so no security issues are being raised. For example. if there are no rules corresponding to a given OWASP category activated in your quality profile, you won’t get issues linked to that specific category and the rating displayed will be a dash (-).
* SonarQube Server might not currently have many rules for your programming language, so it won’t raise any issues or only a few security issues are being recognized.

## Downloading a PDF copy <a href="#download-a-pdf-copy" id="download-a-pdf-copy"></a>

You can download a PDF copy of your security report for projects and applications:

<figure><img src="/files/GlHuH4PexZnuZNOWsRJC" alt="Downloading a PDF copy of your security report"><figcaption></figcaption></figure>

1. Retrieve your project or application. See [Retrieving projects](/sonarqube-server/user-guide/viewing-projects/retrieving-projects.md) for more information.
2. Go to **Security reports** and select **Download security report (PDF)**.

The PDF contains:

* The number of open Security Vulnerabilities (in Standard Experience) or Security issues (in MQR Mode) and the security rating on both overall code and new code.
* The number of Security Hotspots, the percentage of reviewed Security Hotspots, and the security review rating on both overall and new code.
* Your Sonar, OWASP, CWE reports.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [PDF reports](/sonarqube-server/user-guide/viewing-reports/pdf-reports.md)
* [Regulatory reports](/sonarqube-server/user-guide/viewing-reports/regulatory-reports.md)
* [Portfolios](/sonarqube-server/user-guide/viewing-reports/portfolios.md)
* [Reviewing and fixing dependency risks](/sonarqube-server/advanced-security/reviewing-and-fixing-dependency-risks.md#downloading-a-dependency-risk-report)
* [Cyber Resilience Act capability mapping](https://docs.sonarsource.com/cyber-resilience-act)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sonarsource.com/sonarqube-server/user-guide/viewing-reports/security-reports.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
