org.owasp.dependencycheck.utils.DownloadFailedException: Error making HTTP HEAD request.

495 views
Skip to first unread message

Prashanth Srikanthan

unread,
May 13, 2014, 3:04:49 PM5/13/14
to dependen...@googlegroups.com
I receive the following error when I run the batch file on Windows. Any idea how to resolve this ?

-------------------------

May 13, 2014 1:59:02 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Database User: dcuser
May 13, 2014 1:59:03 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory createTables
FINE: Creating database structure
May 13, 2014 1:59:26 PM org.owasp.dependencycheck.data.update.NvdCveUpdater update
WARNING: Unable to download the NVD CVE data, unable to update the data to use the most current data.
May 13, 2014 1:59:26 PM org.owasp.dependencycheck.data.update.NvdCveUpdater update
FINE: null
org.owasp.dependencycheck.utils.DownloadFailedException: Error making HTTP HEAD request.
    at org.owasp.dependencycheck.utils.Downloader.getLastModified(Downloader.java:183)
    at org.owasp.dependencycheck.data.update.UpdateableNvdCve.add(UpdateableNvdCve.java:96)
    at org.owasp.dependencycheck.data.update.StandardUpdate.retrieveCurrentTimestampsFromWeb(StandardUpdate.java:272)
    at org.owasp.dependencycheck.data.update.StandardUpdate.updatesNeeded(StandardUpdate.java:203)
    at org.owasp.dependencycheck.data.update.StandardUpdate.<init>(StandardUpdate.java:90)
    at org.owasp.dependencycheck.data.update.NvdCveUpdater.update(NvdCveUpdater.java:47)
    at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:437)
    at org.owasp.dependencycheck.Engine.<init>(Engine.java:108)
    at org.owasp.dependencycheck.Engine.<init>(Engine.java:84)
    at org.owasp.dependencycheck.App.runScan(App.java:113)
    at org.owasp.dependencycheck.App.run(App.java:96)
    at org.owasp.dependencycheck.App.main(App.java:63)
Caused by: java.net.NoRouteToHostException: No route to host: connect
    at java.net.PlainSocketImpl.socketConnect(Native Method)
    at java.net.PlainSocketImpl.doConnect(Unknown Source)
    at java.net.PlainSocketImpl.connectToAddress(Unknown Source)
    at java.net.PlainSocketImpl.connect(Unknown Source)
    at java.net.Socket.connect(Unknown Source)
    at sun.net.NetworkClient.doConnect(Unknown Source)
    at sun.net.www.http.HttpClient.openServer(Unknown Source)
    at sun.net.www.http.HttpClient.openServer(Unknown Source)
    at sun.net.www.http.HttpClient.<init>(Unknown Source)
    at sun.net.www.http.HttpClient.New(Unknown Source)
    at sun.net.www.http.HttpClient.New(Unknown Source)
    at sun.net.www.protocol.http.HttpURLConnection.getNewHttpClient(Unknown Source)
    at sun.net.www.protocol.http.HttpURLConnection.plainConnect(Unknown Source)
    at sun.net.www.protocol.http.HttpURLConnection.connect(Unknown Source)
    at org.owasp.dependencycheck.utils.Downloader.getLastModified(Downloader.java:178)
    ... 11 more
May 13, 2014 1:59:29 PM org.owasp.dependencycheck.Engine analyzeDependencies
SEVERE: No documents exist

Unable to continue dependency-check analysis.
May 13, 2014 1:59:29 PM org.owasp.dependencycheck.Engine analyzeDependencies
FINE: null
org.owasp.dependencycheck.exception.NoDataException: No documents exist
    at org.owasp.dependencycheck.Engine.ensureDataExists(Engine.java:502)
    at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:314)
    at org.owasp.dependencycheck.App.runScan(App.java:119)
    at org.owasp.dependencycheck.App.run(App.java:96)
    at org.owasp.dependencycheck.App.main(App.java:63)
May 13, 2014 1:59:29 PM org.owasp.dependencycheck.data.nvdcve.CveDB finalize
FINE: Entering finalize
May 13, 2014 1:59:29 PM org.owasp.dependencycheck.data.nvdcve.CveDB finalize
FINE: Entering finalize

---------------------------

Prashanth Srikanthan

unread,
May 13, 2014, 4:15:53 PM5/13/14
to dependen...@googlegroups.com
I was able to provide the proxy settings with the -u and -p options and worked perfectly.

Jeremy Long

unread,
May 13, 2014, 7:51:38 PM5/13/14
to Prashanth Srikanthan, dependen...@googlegroups.com
Correct - I think I should update the error message to indicate that the proxy settings may need to be set/checked....  

--Jeremy


--
You received this message because you are subscribed to the Google Groups "Dependency Check" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dependency-che...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Prashanth Srikanthan

unread,
Mar 30, 2015, 12:04:23 PM3/30/15
to dependen...@googlegroups.com, psrik...@gmail.com
Hi Jeremy,

Now, I am receiving the following error. I am behind a proxy and I am providing the proxy details when I am running dependency check. Any idea why the connection could be reset ?

Mar 30, 2015 11:03:54 AM org.owasp.dependencycheck.data.update.StandardUpdate update
INFO: NVD CVE requires several updates; this could take a couple of minutes.
Mar 30, 2015 11:03:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2002
Mar 30, 2015 11:03:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2003
Mar 30, 2015 11:03:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2004
Mar 30, 2015 11:03:57 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2003
Mar 30, 2015 11:03:57 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2005
Mar 30, 2015 11:03:57 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2003
Mar 30, 2015 11:03:58 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2004
Mar 30, 2015 11:03:58 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2006
Mar 30, 2015 11:04:01 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2002
Mar 30, 2015 11:04:01 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2007
Mar 30, 2015 11:04:01 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2004
Mar 30, 2015 11:04:01 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2002
Mar 30, 2015 11:04:02 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2005
Mar 30, 2015 11:04:02 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2005
Mar 30, 2015 11:04:02 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2008
Mar 30, 2015 11:04:09 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2007
Mar 30, 2015 11:04:09 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2007
Mar 30, 2015 11:04:09 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2009
Mar 30, 2015 11:04:10 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2008
Mar 30, 2015 11:04:10 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2010
Mar 30, 2015 11:04:10 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2008
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2009
Some CVEs may not be reported.
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: null
org.owasp.dependencycheck.utils.DownloadFailedException: Error saving downloaded file.
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:126)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:59)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:186)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask$Sync.innerRun(Unknown Source)
at java.util.concurrent.FutureTask.run(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
Caused by: java.net.SocketException: Connection reset
at java.net.SocketInputStream.read(Unknown Source)
at java.io.BufferedInputStream.fill(Unknown Source)
at java.io.BufferedInputStream.read1(Unknown Source)
at java.io.BufferedInputStream.read(Unknown Source)
at sun.net.www.MeteredStream.read(Unknown Source)
at java.io.FilterInputStream.read(Unknown Source)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(Unknown Source)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(Unknown Source)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:122)
... 8 more
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.data.update.StandardUpdate update
FINE: Thread was interrupted during download
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2011
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.Engine doUpdates
WARNING: Unable to update Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
Mar 30, 2015 11:04:11 AM org.owasp.dependencycheck.Engine doUpdates
FINE: Unable to update details for org.owasp.dependencycheck.data.update.NvdCveUpdater
org.owasp.dependencycheck.data.update.exception.UpdateException: The download was interrupted; unable to complete the update
at org.owasp.dependencycheck.data.update.StandardUpdate.update(StandardUpdate.java:154)
at org.owasp.dependencycheck.data.update.NvdCveUpdater.update(NvdCveUpdater.java:50)
at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:437)
at org.owasp.dependencycheck.Engine.<init>(Engine.java:108)
at org.owasp.dependencycheck.Engine.<init>(Engine.java:84)
at org.owasp.dependencycheck.App.runScan(App.java:113)
at org.owasp.dependencycheck.App.run(App.java:96)
at org.owasp.dependencycheck.App.main(App.java:63)
Mar 30, 2015 11:04:17 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2006
Some CVEs may not be reported.

--Prashanth

Jeremy Long

unread,
Mar 31, 2015, 5:56:32 AM3/31/15
to Prashanth Srikanthan, dependen...@googlegroups.com
In attempting to debug this - can you add '--connectiontimeout 60000' and let me know if that resolves the issue?

Thanks,

Jeremy

Prashanth Srikanthan

unread,
Mar 31, 2015, 9:59:59 AM3/31/15
to dependen...@googlegroups.com, psrik...@gmail.com
That did not resolve the issue.

Mar 31, 2015 9:52:36 AM org.owasp.dependencycheck.data.update.StandardUpdate update
INFO: NVD CVE requires several updates; this could take a couple of minutes.
Mar 31, 2015 9:52:36 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2002
Mar 31, 2015 9:52:36 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2003
Mar 31, 2015 9:52:36 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2004
Mar 31, 2015 9:52:41 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2003
Mar 31, 2015 9:52:41 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2005
Mar 31, 2015 9:52:41 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2003
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2004
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2004
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2006
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2002
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2007
Mar 31, 2015 9:52:47 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2002
Mar 31, 2015 9:52:49 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2005
Mar 31, 2015 9:52:49 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2005
Mar 31, 2015 9:52:49 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2008
Mar 31, 2015 9:52:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2006
Some CVEs may not be reported.
Mar 31, 2015 9:52:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2009
Mar 31, 2015 9:52:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2009
Some CVEs may not be reported.
Mar 31, 2015 9:52:55 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2010
Mar 31, 2015 9:52:59 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2007
Mar 31, 2015 9:52:59 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2011
Mar 31, 2015 9:52:59 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2007
Mar 31, 2015 9:53:07 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2008
Mar 31, 2015 9:53:07 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2008
Mar 31, 2015 9:53:07 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2012
Mar 31, 2015 9:53:20 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2010
Mar 31, 2015 9:53:20 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2013
Mar 31, 2015 9:53:20 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2010
Mar 31, 2015 9:53:29 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2012
Mar 31, 2015 9:53:29 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2012
Mar 31, 2015 9:53:29 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2014
Mar 31, 2015 9:53:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2013
Mar 31, 2015 9:53:47 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2015
Mar 31, 2015 9:53:47 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2013
Mar 31, 2015 9:53:50 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2015
Mar 31, 2015 9:53:50 AM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2015
Mar 31, 2015 9:53:50 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - Modified
Mar 31, 2015 9:53:50 AM org.owasp.dependencycheck.Engine doUpdates
WARNING: Unable to update Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
Mar 31, 2015 9:53:52 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2014
Mar 31, 2015 9:53:52 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - 2014
Some CVEs may not be reported.
Mar 31, 2015 9:53:53 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - Modified
Mar 31, 2015 9:53:53 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - Modified
Some CVEs may not be reported.
Mar 31, 2015 9:54:02 AM org.owasp.dependencycheck.Engine analyzeDependencies
SEVERE: No documents exist

Unable to continue dependency-check analysis.
Mar 31, 2015 9:54:12 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2011
Mar 31, 2015 9:54:12 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - 2011
Some CVEs may not be reported.

Also, I saw this exception in the logs.

Mar 31, 2015 9:54:44 AM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: Download Task Failed
java.util.concurrent.RejectedExecutionException
at java.util.concurrent.ThreadPoolExecutor$AbortPolicy.rejectedExecution(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor.reject(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor.execute(Unknown Source)
at java.util.concurrent.AbstractExecutorService.submit(Unknown Source)
at java.util.concurrent.Executors$DelegatedExecutorService.submit(Unknown Source)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:203)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask$Sync.innerRun(Unknown Source)
at java.util.concurrent.FutureTask.run(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
Mar 31, 2015 9:54:47 AM org.owasp.dependencycheck.Engine analyzeDependencies
SEVERE: No documents exist


Thanks
Prashanth

Jeremy Long

unread,
Mar 31, 2015, 12:12:44 PM3/31/15
to Prashanth Srikanthan, dependen...@googlegroups.com
Okay... next attempt. What if you use the actual java system properties to set the HTTP Proxy instead of using the dependency-check command line options: https://docs.oracle.com/javase/6/docs/technotes/guides/net/proxies.html

Also, could you provide the full log file and tell me what OS and JVM you are using?

Thanks!

Jeremy

Prashanth Srikanthan

unread,
Mar 31, 2015, 2:18:21 PM3/31/15
to dependen...@googlegroups.com, psrik...@gmail.com
Here is the full log file. Will try the system properties and get back to you.

Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: data.directory='D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\bin\..\data'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: autoupdate='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: proxy.server='xxxxxxxxxxxxx'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: proxy.port='80'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: proxy.username='xxxxxx'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: proxy.password='xxxxxxxx'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setString
FINE: Setting: connection.timeout='120000'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.jar.enabled='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.archive.enabled='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.nuspec.enabled='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.assembly.enabled='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.nexus.enabled='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings setBoolean
FINE: Setting: analyzer.nexus.proxy='true'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Loading driver: org.h2.Driver
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings getDataFile
FINE: Settings.getDataFile() - file: 'D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\bin\..\data'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings getConnectionString
FINE: Connection String: 'jdbc:h2:file:D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\data\cve.2.9;FILE_LOCK=SERIALIZED;AUTOCOMMIT=ON;'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.utils.Settings getDataFile
FINE: Settings.getDataFile() - file: 'D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\bin\..\data'
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Need to create DB Structure: true
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Loading database connection
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Connection String: jdbc:h2:file:D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\data\cve.2.9;FILE_LOCK=SERIALIZED;AUTOCOMMIT=ON;
Mar 31, 2015 2:05:54 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory initialize
FINE: Database User: dcuser
Mar 31, 2015 2:05:56 PM org.owasp.dependencycheck.data.nvdcve.ConnectionFactory createTables
FINE: Creating database structure
Mar 31, 2015 2:06:00 PM org.owasp.dependencycheck.data.update.StandardUpdate update
INFO: NVD CVE requires several updates; this could take a couple of minutes.
Mar 31, 2015 2:06:00 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2002
Mar 31, 2015 2:06:00 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2003
Mar 31, 2015 2:06:00 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2004
Mar 31, 2015 2:06:03 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2003
Mar 31, 2015 2:06:03 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2005
Mar 31, 2015 2:06:03 PM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2003
Mar 31, 2015 2:06:06 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2004
Mar 31, 2015 2:06:06 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2006
Mar 31, 2015 2:06:06 PM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2004
Mar 31, 2015 2:06:07 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2002
Mar 31, 2015 2:06:07 PM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2002
Mar 31, 2015 2:06:07 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2007
Mar 31, 2015 2:06:10 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2005
Mar 31, 2015 2:06:10 PM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2005
Mar 31, 2015 2:06:10 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2008
Mar 31, 2015 2:06:17 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2007
Mar 31, 2015 2:06:17 PM org.owasp.dependencycheck.data.update.task.ProcessTask processFiles
INFO: Processing Started for NVD CVE - 2007
Mar 31, 2015 2:06:17 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2009
Mar 31, 2015 2:06:18 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2009
Some CVEs may not be reported.
Mar 31, 2015 2:06:18 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: null
org.owasp.dependencycheck.utils.DownloadFailedException: Error saving downloaded file.
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:126)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:59)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:186)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:744)
Caused by: java.net.SocketException: Connection reset
at java.net.SocketInputStream.read(SocketInputStream.java:196)
at java.net.SocketInputStream.read(SocketInputStream.java:122)
at java.io.BufferedInputStream.fill(BufferedInputStream.java:235)
at java.io.BufferedInputStream.read1(BufferedInputStream.java:275)
at java.io.BufferedInputStream.read(BufferedInputStream.java:334)
at sun.net.www.MeteredStream.read(MeteredStream.java:134)
at java.io.FilterInputStream.read(FilterInputStream.java:133)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(HttpURLConnection.java:3053)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(HttpURLConnection.java:3047)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:122)
... 7 more

Mar 31, 2015 2:06:18 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2010
Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: Download Failed for NVD CVE - 2006
Some CVEs may not be reported.
Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: null
org.owasp.dependencycheck.utils.DownloadFailedException: Error saving downloaded file.
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:126)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:59)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:186)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:744)
Caused by: java.net.SocketException: Connection reset
at java.net.SocketInputStream.read(SocketInputStream.java:196)
at java.net.SocketInputStream.read(SocketInputStream.java:122)
at java.io.BufferedInputStream.fill(BufferedInputStream.java:235)
at java.io.BufferedInputStream.read1(BufferedInputStream.java:275)
at java.io.BufferedInputStream.read(BufferedInputStream.java:334)
at sun.net.www.MeteredStream.read(MeteredStream.java:134)
at java.io.FilterInputStream.read(FilterInputStream.java:133)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(HttpURLConnection.java:3053)
at sun.net.www.protocol.http.HttpURLConnection$HttpInputStream.read(HttpURLConnection.java:3047)
at org.owasp.dependencycheck.utils.Downloader.fetchFile(Downloader.java:122)
... 7 more

Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Started for NVD CVE - 2011
Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.data.update.StandardUpdate update
FINE: Thread was interrupted during download
Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.Engine doUpdates
WARNING: Unable to update Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
Mar 31, 2015 2:06:23 PM org.owasp.dependencycheck.Engine doUpdates
FINE: Unable to update details for org.owasp.dependencycheck.data.update.NvdCveUpdater
org.owasp.dependencycheck.data.update.exception.UpdateException: The download was interrupted; unable to complete the update
at org.owasp.dependencycheck.data.update.StandardUpdate.update(StandardUpdate.java:154)
at org.owasp.dependencycheck.data.update.NvdCveUpdater.update(NvdCveUpdater.java:50)
at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:437)
at org.owasp.dependencycheck.Engine.<init>(Engine.java:108)
at org.owasp.dependencycheck.Engine.<init>(Engine.java:84)
at org.owasp.dependencycheck.App.runScan(App.java:113)
at org.owasp.dependencycheck.App.run(App.java:96)
at org.owasp.dependencycheck.App.main(App.java:63)

Mar 31, 2015 2:06:26 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2008
Mar 31, 2015 2:06:26 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - 2008
Some CVEs may not be reported.
Mar 31, 2015 2:06:26 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: Download Task Failed
java.util.concurrent.RejectedExecutionException: Task java.util.concurrent.FutureTask@1b228d1 rejected from java.util.concurrent.ThreadPoolExecutor@195ecae[Terminated, pool size = 0, active threads = 0, queued tasks = 0, completed tasks = 5]
at java.util.concurrent.ThreadPoolExecutor$AbortPolicy.rejectedExecution(ThreadPoolExecutor.java:2048)
at java.util.concurrent.ThreadPoolExecutor.reject(ThreadPoolExecutor.java:821)
at java.util.concurrent.ThreadPoolExecutor.execute(ThreadPoolExecutor.java:1372)
at java.util.concurrent.AbstractExecutorService.submit(AbstractExecutorService.java:132)
at java.util.concurrent.Executors$DelegatedExecutorService.submit(Executors.java:641)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:203)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:744)

Mar 31, 2015 2:06:30 PM org.owasp.dependencycheck.Engine analyzeDependencies
SEVERE: No documents exist

Unable to continue dependency-check analysis.
Mar 31, 2015 2:06:30 PM org.owasp.dependencycheck.Engine analyzeDependencies
FINE: null
org.owasp.dependencycheck.exception.NoDataException: No documents exist
at org.owasp.dependencycheck.Engine.ensureDataExists(Engine.java:502)
at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:314)
at org.owasp.dependencycheck.App.runScan(App.java:119)
at org.owasp.dependencycheck.App.run(App.java:96)
at org.owasp.dependencycheck.App.main(App.java:63)

Mar 31, 2015 2:06:32 PM org.owasp.dependencycheck.data.nvdcve.CveDB finalize
FINE: Entering finalize
Mar 31, 2015 2:06:38 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2010
Mar 31, 2015 2:06:38 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - 2010
Some CVEs may not be reported.
Mar 31, 2015 2:06:38 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: Download Task Failed
java.util.concurrent.RejectedExecutionException: Task java.util.concurrent.FutureTask@215e72 rejected from java.util.concurrent.ThreadPoolExecutor@195ecae[Terminated, pool size = 0, active threads = 0, queued tasks = 0, completed tasks = 5]
at java.util.concurrent.ThreadPoolExecutor$AbortPolicy.rejectedExecution(ThreadPoolExecutor.java:2048)
at java.util.concurrent.ThreadPoolExecutor.reject(ThreadPoolExecutor.java:821)
at java.util.concurrent.ThreadPoolExecutor.execute(ThreadPoolExecutor.java:1372)
at java.util.concurrent.AbstractExecutorService.submit(AbstractExecutorService.java:132)
at java.util.concurrent.Executors$DelegatedExecutorService.submit(Executors.java:641)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:203)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:744)

Mar 31, 2015 2:07:17 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
INFO: Download Complete for NVD CVE - 2011
Mar 31, 2015 2:07:17 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
WARNING: An exception occurred downloading NVD CVE - 2011
Some CVEs may not be reported.
Mar 31, 2015 2:07:17 PM org.owasp.dependencycheck.data.update.task.DownloadTask call
FINE: Download Task Failed
java.util.concurrent.RejectedExecutionException: Task java.util.concurrent.FutureTask@902478 rejected from java.util.concurrent.ThreadPoolExecutor@195ecae[Terminated, pool size = 0, active threads = 0, queued tasks = 0, completed tasks = 5]
at java.util.concurrent.ThreadPoolExecutor$AbortPolicy.rejectedExecution(ThreadPoolExecutor.java:2048)
at java.util.concurrent.ThreadPoolExecutor.reject(ThreadPoolExecutor.java:821)
at java.util.concurrent.ThreadPoolExecutor.execute(ThreadPoolExecutor.java:1372)
at java.util.concurrent.AbstractExecutorService.submit(AbstractExecutorService.java:132)
at java.util.concurrent.Executors$DelegatedExecutorService.submit(Executors.java:641)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:203)
at org.owasp.dependencycheck.data.update.task.DownloadTask.call(DownloadTask.java:40)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:744)


Thanks
Prashanth

Jeremy Long

unread,
Apr 1, 2015, 5:30:24 AM4/1/15
to Prashanth Srikanthan, dependen...@googlegroups.com
From the log file it appears you are using an older version of dependency-check:


'D:\Tools\OWASP DEPENDENCY CHECK\dependency-check-1.2.4-release\bin\..\data'

In 1.2.5 several URLs were changed to pull a different set of files from the NVD. I would highly recommend upgrading to 1.2.9 and seeing if the problem still exists.  Additionally, I anticipate releasing 1.2.10 within a week.

Best Regards,

Jeremy

Prashanth Srikanthan

unread,
Apr 1, 2015, 10:35:39 AM4/1/15
to dependen...@googlegroups.com, psrik...@gmail.com
That could be the problem. I might have to test it with the newer version. Does these URLs change often ? Does that mean the older versions of Dependency Check are unusable ?

Regards
Prashanth
...

Prashanth Srikanthan

unread,
Apr 1, 2015, 11:13:40 AM4/1/15
to dependen...@googlegroups.com, psrik...@gmail.com
Hi Jeremy,

I was able to test it with a new version and it worked fine. Looks like we need to upgrade to a newer version. Thanks for all your help.

Regards
Prashanth
...

Jeremy Long

unread,
Apr 3, 2015, 5:37:03 AM4/3/15
to Prashanth Srikanthan, dependen...@googlegroups.com
Glad you were able to get things to work. With regard to the URLs changing - no, they do not change often. In fact, I believe the change at 1.2.5 has been the only change to the URLs. Due to this fact, the older versions are not very useable without some configuration changes.


--Jeremy

--
Reply all
Reply to author
Forward
0 new messages