CWE
Home > CWE List > CWE- Individual Dictionary Definition (1.0.1)  
Search by ID:

CWE-115: Misinterpretation of Input

Individual Definition in a New Window
Misinterpretation of Input
Status: Incomplete
Weakness ID: 115 (Weakness Base)
Description
Summary

The software misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

Observed Examples
ReferenceDescription
Product does not correctly import and process security settings from another product.
Product sees dangerous file extension in free text of a group discussion, disconnects all users.
Research Gaps

This concept needs further study. It is likely a factor in several weaknesses, possibly resultant as well. Overlaps Multiple Interpretation Errors (MIE).

Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfWeakness ClassWeakness ClassWeakness Class20Insufficient Input Validation
Development Concepts (primary)699
Research Concepts (primary)1000
CanAlsoBeWeakness BaseWeakness BaseWeakness Base436Interpretation Conflict
Research Concepts1000
Taxonomy Mappings
Mapped Taxonomy NameMapped Node Name
PLOVERMisinterpretation Error
Applicable Platforms
Languages
All
Time of Introduction
* Architecture and Design
* Implementation
* Operation
Content History
Submissions
PLOVER. (Externally Mined)
Modifications
Eric Dalci. Cigital. 2008-07-01. (External)
updated Time_of_Introduction
CWE Content Team. MITRE. 2008-09-08. (Internal)
updated Relationships, Taxonomy_Mappings
Previous Entry Names
* Misinterpretation Error (changed 2008-04-11)
Page Last Updated: October 16, 2008