Look at JVM exploits from the last years. They're usually chains of quite clever hops, for example from a serialisation or deserialisation vulnerability. Sonar is not going to help you with that and when something like it pops up it might already have been used 'in the wild' for some time, and then you have the problem of rolling out patches into the field.
You'd be better off going back to Ada.