CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | Base | Simple | Draft | |
| CWE-202 | Exposure of Sensitive Information Through Data Queries | Base | Simple | Draft | |
| CWE-203 | Observable Discrepancy | Base | Simple | Incomplete | |
| CWE-204 | Observable Response Discrepancy | Base | Simple | Incomplete | |
| CWE-205 | Observable Behavioral Discrepancy | Base | Simple | Incomplete | |
| CWE-206 | Observable Internal Behavioral Discrepancy | Variant | Simple | Incomplete | |
| CWE-207 | Observable Behavioral Discrepancy With Equivalent Products | Variant | Simple | Draft | |
| CWE-208 | Observable Timing Discrepancy | Base | Simple | Incomplete | |
| CWE-209 | Generation of Error Message Containing Sensitive Information | Base | Simple | Draft | |
| CWE-210 | Self-generated Error Message Containing Sensitive Information | Base | Simple | Draft | |
| CWE-211 | Externally-Generated Error Message Containing Sensitive Information | Base | Simple | Incomplete | |
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | Base | Simple | Incomplete | |
| CWE-213 | Exposure of Sensitive Information Due to Incompatible Policies | Base | Simple | Draft | |
| CWE-214 | Invocation of Process Using Visible Sensitive Information | Base | Simple | Incomplete | |
| CWE-215 | Insertion of Sensitive Information Into Debugging Code | Base | Simple | Draft | |
| CWE-216 | DEPRECATED: Containment Errors (Container Errors) | Class | Simple | Deprecated | |
| CWE-217 | DEPRECATED: Failure to Protect Stored Data from Modification | Base | Simple | Deprecated | |
| CWE-218 | DEPRECATED: Failure to provide confidentiality for stored data | Base | Simple | Deprecated | |
| CWE-219 | Storage of File with Sensitive Data Under Web Root | Variant | Simple | Draft | |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Base | Simple | Stable |