<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security concerns with the java code that Talend creates in Talend Studio</title>
    <link>https://community.qlik.com/t5/Talend-Studio/Security-concerns-with-the-java-code-that-Talend-creates/m-p/2366108#M129635</link>
    <description>&lt;P&gt;I have generated multiple ETL jobs to move data from one database to another and ran a couple scans on the code that was created.&amp;nbsp; The scans found many security flaws when scanning based on the Security Technical Implementation Guide (STIG).&amp;nbsp; Does Talend support this security guide and does Talend update their software when security concerns are found?&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 18:00:31 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2016-05-24T18:00:31Z</dc:date>
    <item>
      <title>Security concerns with the java code that Talend creates</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Security-concerns-with-the-java-code-that-Talend-creates/m-p/2366108#M129635</link>
      <description>&lt;P&gt;I have generated multiple ETL jobs to move data from one database to another and ran a couple scans on the code that was created.&amp;nbsp; The scans found many security flaws when scanning based on the Security Technical Implementation Guide (STIG).&amp;nbsp; Does Talend support this security guide and does Talend update their software when security concerns are found?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 18:00:31 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Security-concerns-with-the-java-code-that-Talend-creates/m-p/2366108#M129635</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2016-05-24T18:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Security concerns with the java code that Talend creates</title>
      <link>https://community.qlik.com/t5/Talend-Studio/Security-concerns-with-the-java-code-that-Talend-creates/m-p/2366109#M129636</link>
      <description>I would say, STIG cannot be applied to generated code without any user interaction. Of course nobody e.g. would write SQL code with direct inline values but this code cannot misused because the purpose of the jobs are batch processing and this is not affected by the attempt of users to cheat the system.&amp;nbsp;&lt;BR /&gt;By the way, the database output components uses always prepared statements and therefore secure.</description>
      <pubDate>Tue, 24 May 2016 22:51:14 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/Security-concerns-with-the-java-code-that-Talend-creates/m-p/2366109#M129636</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2016-05-24T22:51:14Z</dc:date>
    </item>
  </channel>
</rss>

