CWE 弱点
CWE 基础字段与弱点分类查询。
| CWE ID | 名称 | 抽象级别 | 结构 | 状态 | 操作 |
|---|---|---|---|---|---|
| CWE-281 | Improper Preservation of Permissions | Base | Simple | Draft | |
| CWE-282 | Improper Ownership Management | Class | Simple | Draft | |
| CWE-283 | Unverified Ownership | Base | Simple | Draft | |
| CWE-284 | Improper Access Control | Pillar | Simple | Incomplete | |
| CWE-285 | Improper Authorization | Class | Simple | Draft | |
| CWE-286 | Incorrect User Management | Class | Simple | Incomplete | |
| CWE-287 | Improper Authentication | Class | Simple | Draft | |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | Base | Simple | Incomplete | |
| CWE-289 | Authentication Bypass by Alternate Name | Base | Simple | Incomplete | |
| CWE-29 | Path Traversal: '\..\filename' | Variant | Simple | Incomplete | |
| CWE-290 | Authentication Bypass by Spoofing | Base | Simple | Incomplete | |
| CWE-291 | Reliance on IP Address for Authentication | Variant | Simple | Incomplete | |
| CWE-292 | DEPRECATED: Trusting Self-reported DNS Name | Variant | Simple | Deprecated | |
| CWE-293 | Using Referer Field for Authentication | Variant | Simple | Draft | |
| CWE-294 | Authentication Bypass by Capture-replay | Base | Simple | Incomplete | |
| CWE-295 | Improper Certificate Validation | Base | Simple | Draft | |
| CWE-296 | Improper Following of a Certificate's Chain of Trust | Base | Simple | Draft | |
| CWE-297 | Improper Validation of Certificate with Host Mismatch | Variant | Simple | Incomplete | |
| CWE-298 | Improper Validation of Certificate Expiration | Variant | Simple | Draft | |
| CWE-299 | Improper Check for Certificate Revocation | Base | Simple | Draft |