CWE-221 信息丢失或遗漏
Information Loss or Omission
结构: Simple
Abstraction: Class
状态: Incomplete
被利用可能性: unkown
基本描述
The software does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.
扩展描述
This can be resultant, e.g. a buffer overflow might trigger a crash before the product can log the event.
相关缺陷
适用平台
Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}
常见的影响
范围 | 影响 | 注释 |
---|---|---|
Non-Repudiation | Hide Activities |
分类映射
映射的分类名 | ImNode ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Information loss or omission |
相关攻击模式
- CAPEC-81
文章来源于互联网:scap中文网
- 左青龙
- 微信扫一扫
- 右白虎
- 微信扫一扫
评论