CAST AIP Service Packs 8.3.20 - 8.3.23 are compatible only with the latest releases of the JEE Analyzer extension, i.e. 1.0.28 and 1.2.10-funcrel. Using older releases of the extension with these CAST AIP Service Packs risks incomplete analysis results (missing objects, links, violations, erroneous FP values) for JEE and C++ analyses.

Therefore, when using CAST AIP Service Packs 8.3.20 - 8.3.23, please either:

  • Upgrade your JEE extension to a compatible release (i.e. ≥ 1.0.28 or ≥ 1.2.10-funcrel) OR
  • Upgrade CAST AIP to a more recent Service Pack (≥ 8.3.24) which are compatible with older releases of the JEE Analyzer extension

If upgrading the JEE Analyzer extension or CAST AIP is not possible, please contact CAST Technical Support

Resolved issues

The following issues have been fixed in this release of the JEE Analyzer extension:

Internal IDTicket IDSummary
JFAMILY-90414878Syntax errors in wsdl file should not set the analysis status as 'failed'
JFAMILY-87914661False positive is coming for the rule "Close database resources ASAP"
JFAMILY-87814649"Analysis failing: Error in Java Analysis"
JFAMILY-87512790Violations for "Avoid using ''" are incorectly raised on List<File>
JFAMILY-85914451False positive is coming for rule CWE-672: Expired or Released Resource should not be used

False violations found for quality rule "Pages should use error handling page"

JFAMILY-84012031False positive for the QR- Avoid to use this within Constructor in multi-thread environment
JFAMILY-83911868False Violation for QR 'Pages should use error handling page' when webdefault.xml is included in analysis
JFAMILY-83711709J2EE: Unable to process JSP analysis 'CCE_2b80894c' (An exception occurred)
JFAMILY-77312777"Missing links between Java Interface and Java Bean objects"
JFAMILY-765-Messages "No parametrization trigger found for <method-name>" are flooding the log file of JEE analysis

TCC - Base_Java config file: duplicated value in set "Standard Entry Point - Java - org.apache.camel (GS)"

JFAMILY-650-JEE analysis log file is flooded with useless messages "No parametrization trigger found for <method-name>"