CWE
Home > CWE List > CWE- Individual Dictionary Definition (1.7)  

CWE-264: Permissions, Privileges, and Access Controls

 
Permissions, Privileges, and Access Controls
Category ID: 264 (Category)Status: Incomplete
+ Description

Description Summary

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
+ Applicable Platforms

Languages

All

+ Potential Mitigations
PhaseDescription

Follow the principle of least privilege when assigning access rights to entities in a software system.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfCategoryCategory254Security Features
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class250Execution with Unnecessary Privileges
Development Concepts699
ParentOfCategoryCategory265Privilege / Sandbox Issues
Development Concepts (primary)699
ParentOfCategoryCategory275Permission Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class282Improper Ownership Management
Development Concepts (primary)699
CanAlsoBeWeakness BaseWeakness Base283Unverified Ownership
Research Concepts1000
ParentOfWeakness ClassWeakness Class284Access Control (Authorization) Issues
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class286Incorrect User Management
Development Concepts (primary)699
MemberOfViewView635Weaknesses Used by NVD
Weaknesses Used by NVD (primary)635
+ Taxonomy Mappings
Mapped Taxonomy NameNode IDFitMapped Node Name
PLOVERPermissions, Privileges, and ACLs
+ Content History
Submissions
Submission DateSubmitterOrganizationSource
PLOVERExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships, Taxonomy Mappings
Page Last Updated: December 28, 2009