{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T14:48:24Z","timestamp":1787496504663,"version":"build-2736575974"},"reference-count":87,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"22","license":[{"start":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T00:00:00Z","timestamp":1763164800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2025,11,15]]},"DOI":"10.1109\/jiot.2025.3598235","type":"journal-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T17:35:38Z","timestamp":1755106538000},"page":"46863-46877","source":"Crossref","is-referenced-by-count":3,"title":["Spring Framework Benchmarking Utility for Static Application Security Testing (SAST) Tools"],"prefix":"10.1109","volume":"12","author":[{"given":"Elizaveta","family":"Kuzmina","sequence":"first","affiliation":[{"name":"Whitecliffe Technology and Innovation, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0232-2356","authenticated-orcid":false,"given":"Shahbaz Pervez","family":"Chattha","sequence":"additional","affiliation":[{"name":"Whitecliffe Technology and Innovation, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2947-5582","authenticated-orcid":false,"given":"Seyed Ebrahim","family":"Hosseini","sequence":"additional","affiliation":[{"name":"Whitecliffe Technology and Innovation, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muazma","family":"Shahbaz","sequence":"additional","affiliation":[{"name":"Whitecliffe Technology and Innovation, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8370-9290","authenticated-orcid":false,"given":"Adnan","family":"Akhunzada","sequence":"additional","affiliation":[{"name":"College of Computing and Information Technology, University of Doha for Science and Technology, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ITMS59786.2023.10317708"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ASYU58738.2023.10296747"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12061333"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.3390\/software3010002"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.62915\/2472-2707.1063"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1556\/606.2021.00454"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1002\/spe.3181"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.10.027"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.2507\/31st.daaam.proceedings.078"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev45635.2020.00024"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICICT54344.2022.9850910"},{"key":"ref12","volume-title":"Spring framework.","year":"2024"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.jksuci.2021.09.018"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3101739"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3661167.3661176"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.3390\/s23187978"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-54997-8_34"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3154717"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616262"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/C-CODE.2019.8681007"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3475781"},{"key":"ref22","volume-title":"Git.","year":"2024"},{"key":"ref23","volume-title":"NVD-Home","year":"2024"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3524610.3527895"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2020.04.217"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345659"},{"key":"ref27","volume-title":"Do more with Google on android phones & devices.","year":"2024"},{"key":"ref28","volume-title":"Welcome to the Apache Software Foundation!","year":"2024"},{"key":"ref29","volume-title":"Apache Tomcat\u00ae-Welcome!","year":"2024"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2022.111575"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOMW.2018.8407011"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3661167.3661262"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510214"},{"key":"ref34","volume-title":"FindBugsTM-find bugs in java programs","year":"2024"},{"key":"ref35","volume-title":"GitHub: Let\u2019s build from here.","year":"2024"},{"key":"ref36","volume-title":"Apache Distribution Directory","year":"2024"},{"key":"ref37","volume-title":"Test Suites-NIST Software Assurance Reference Dataset","year":"2024"},{"key":"ref38","volume-title":"CWE-Common Weakness Enumeration","year":"2024"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102470"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3389955"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/iSCI50694.2020.00021"},{"key":"ref42","first-page":"1","article-title":"Inferring the best static analysis tool for null pointer dereference in java source code","volume-title":"Proc. CEUR Workshop","author":"Alqaradaghi"},{"key":"ref43","volume-title":"CWE-2019 CWE Top 25 Most Dangerous Software Errors","year":"2024"},{"key":"ref44","volume-title":"CWE-CWE-476: Null Pointer Dereference (4.15)","year":"2024"},{"key":"ref45","volume-title":"BenchmarkJava","year":"2024"},{"key":"ref46","volume-title":"CWE-CWE top 25 Most Dangerous Software Weaknesses","year":"2024"},{"key":"ref47","volume-title":"CWE VIEW: Research Concepts","year":"2024"},{"key":"ref48","volume-title":"Bug patterns-spring CSRF protection disabled.","year":"2024"},{"key":"ref49","volume-title":"spring-CSRF-disabled.java.","year":"2024"},{"key":"ref50","volume-title":"Disabling CSRF Protections is Security-Sensitive","year":"2024"},{"key":"ref51","volume-title":"Allowing Both Safe and Unsafe HTTP Methods is Security-Sensitive","year":"2024"},{"key":"ref52","volume-title":"Bug patterns-potential JDBC injection (spring JDBC).","year":"2024"},{"key":"ref53","volume-title":"tainted-SQL-string.java.","year":"2024"},{"key":"ref54","volume-title":"Spring-sqli.java.","year":"2024"},{"key":"ref55","volume-title":"Formatting SQL Queries is Security-Sensitive","year":"2024"},{"key":"ref56","volume-title":"Potential code injection when using spring expression.","year":"2024"},{"key":"ref57","volume-title":"Spel-injection.java.","year":"2024"},{"key":"ref58","volume-title":"Tainted-file-path.java.","year":"2024"},{"key":"ref59","volume-title":"HttpSecurity URL Patterns Should be Correctly Ordered","year":"2024"},{"key":"ref60","volume-title":"Having a Permissive Cross-Origin Resource Sharing Policy is Security-Sensitive","year":"2024"},{"key":"ref61","volume-title":"Tainted-url-host.java.","year":"2024"},{"key":"ref62","volume-title":"JSON operations should not be vulnerable to injection attacks","year":"2025"},{"key":"ref63","volume-title":"Juliet Java 1.3-NIST Software Assurance Reference Dataset","year":"2024"},{"key":"ref64","volume-title":"CryptoAPI-bench: A comprehensive benchmark on java cryptographic API misuses.","author":"Afrose","year":"2019"},{"key":"ref65","volume-title":"Threat Modeling Process","year":"2025"},{"key":"ref66","volume-title":"Resources.","year":"2025"},{"key":"ref67","volume-title":"Spring expression language (SpEL).","year":"2025"},{"key":"ref68","volume-title":"Spring security.","year":"2025"},{"key":"ref69","volume-title":"Microsoft Excel","year":"2024"},{"key":"ref70","volume-title":"IntelliJ IDEA\u2013the leading java and Kotlin IDE.","year":"2024"},{"key":"ref71","volume-title":"Java.","year":"2024"},{"key":"ref72","volume-title":"Maven\u2013Welcome to Apache Maven","year":"2024"},{"key":"ref73","volume-title":"H2 database engine.","year":"2024"},{"key":"ref74","volume-title":"Liquibase: Database Change Management & CI\/CD Automation","year":"2024"},{"key":"ref75","volume-title":"Postman API Platform","year":"2024"},{"key":"ref76","volume-title":"CWE-23: Relative Path Traversal","year":"2024"},{"key":"ref77","volume-title":"CWE-564: SQL Injection: Hibernate","year":"2024"},{"key":"ref78","volume-title":"CWE-89: Improper Neutralization of Special Elements Used in an SQL Command (\u2018SQL injection\u2019)","year":"2024"},{"key":"ref79","volume-title":"CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (\u2018Eval injection\u2019)","year":"2024"},{"key":"ref80","volume-title":"CWE-285: Improper Authorization","year":"2024"},{"key":"ref81","volume-title":"CWE-352: Cross-Site Request Forgery (CSRF)","year":"2024"},{"key":"ref82","volume-title":"CWE-918: Server-Side Request Forgery (SSRF)","year":"2024"},{"key":"ref83","volume-title":"CWE-942: Permissive Cross-Domain Policy with Untrusted Domains","year":"2024"},{"key":"ref84","volume-title":"CWE-76: Improper Neutralization of Equivalent Special Elements","year":"2025"},{"key":"ref85","volume-title":"Find Security Bugs","author":"Arteau","year":"2024"},{"key":"ref86","volume-title":"Data-Flow Analysis Engine Overview","year":"2024"},{"key":"ref87","volume-title":"Reactive.","year":"2024"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6488907\/11231115\/11124241.pdf?arnumber=11124241","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T18:12:31Z","timestamp":1762539151000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11124241\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,15]]},"references-count":87,"journal-issue":{"issue":"22"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2025.3598235","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,15]]}}}