Scope | Impact | Likelihood |
---|---|---|
Confidentiality | Read Application Data Note: The data read may not be properly secured, it might be viewed by an attacker. | |
Access Control | Bypass Protection Mechanism, Gain Privileges or Assume Identity Note: Trust afforded to the system in question may allow for spoofing or redirection attacks. | |
Access Control | Gain Privileges or Assume Identity Note: If the certificate is not checked, it may be possible for a redirection or spoofing attack to allow a malicious host with a valid certificate to provide data under the guise of a trusted host. While the attacker in question may have a valid certificate, it may simply be a valid certificate for a different site. In order to ensure data integrity, we must check that the certificate is valid, and that it pertains to the site we wish to access. |
Name | Organization | Date | Date release | Version |
---|---|---|---|---|
CWE Community | Draft 5 |
Name | Organization | Date | Comment |
---|---|---|---|
Eric Dalci | Cigital | updated Time_of_Introduction | |
CWE Content Team | MITRE | updated Common_Consequences, Relationships, Other_Notes | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Description | |
CWE Content Team | MITRE | updated Common_Consequences, Other_Notes | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Demonstrative_Examples, Description, Name, Relationship_Notes, Relationships | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Modes_of_Introduction, Relationships | |
CWE Content Team | MITRE | updated Demonstrative_Examples | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Description | |
CWE Content Team | MITRE | updated Modes_of_Introduction, Relationships, Time_of_Introduction | |
CWE Content Team | MITRE | updated Mapping_Notes |