Modes Of Introduction
Implementation
Applicable Platforms
Language
Class: Not Language-Specific (Undetermined)
Technologies
Class: Not Technology-Specific (Undetermined)
Common Consequences
| Scope |
Impact |
Likelihood |
Integrity Access Control | Alter Execution Logic, Bypass Protection Mechanism
Note: An incomplete comparison can lead to resultant weaknesses, e.g., by operating on the wrong object or making a security decision without considering a required factor. | |
Observed Examples
| References |
Description |
| PHP remote file inclusion in web application that filters "http" and "https" URLs, but not "ftp". |
| Product does not prevent access to restricted directories due to partial string comparison with a public directory |
Detection Methods
Manual Static Analysis
Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.
Vulnerability Mapping Notes
Justification : This CWE entry is a Class and might have Base-level children that would be more appropriate
Comment : Examine children of this entry to see if there is a better fit
Submission
| Name |
Organization |
Date |
Date release |
Version |
| CWE Content Team |
MITRE |
2018-01-04 +00:00 |
2018-03-29 +00:00 |
3.1 |
Modifications
| Name |
Organization |
Date |
Comment |
| CWE Content Team |
MITRE |
2019-01-03 +00:00 |
updated Relationships |
| CWE Content Team |
MITRE |
2020-02-24 +00:00 |
updated Description, Relationships, Type |
| CWE Content Team |
MITRE |
2021-03-15 +00:00 |
updated Demonstrative_Examples |
| CWE Content Team |
MITRE |
2023-01-31 +00:00 |
updated Description |
| CWE Content Team |
MITRE |
2023-04-27 +00:00 |
updated Relationships |
| CWE Content Team |
MITRE |
2023-06-29 +00:00 |
updated Mapping_Notes |
| CWE Content Team |
MITRE |
2023-10-26 +00:00 |
updated Observed_Examples |
| CWE Content Team |
MITRE |
2025-12-11 +00:00 |
updated Applicable_Platforms, Common_Consequences, Description |
| CWE Content Team |
MITRE |
2026-04-30 +00:00 |
updated Detection_Factors, Potential_Mitigations |