CWE-281: Improper Preservation of Permissions
Improper Preservation of Permissions
Weakness ID: 281 (Weakness Base) Status: Draft
Description
Description Summary
The software does not preserve permissions or incorrectly
preserves permissions when copying, restoring, or sharing objects, which can
cause them to have less restrictive permissions than
intended.
Time of Introduction
Architecture and Design
Implementation
Operation
Observed Examples
Reference Description
SUNALERT:27807
CVE-2001-1515 Automatic modification of permissions inherited
from another file system.
CVE-2005-1920 Permissions on backup file are created with
defaults, possibly less secure than original
file.
CVE-2001-0195 File is made world-readable when being
cloned.
Weakness Ordinalities
Ordinality Description
Resultant
This is resultant from errors that prevent the permissions from being
preserved.
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Permission preservation failure
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships, Taxonomy Mappings,
Weakness Ordinalities 2009-05-27 CWE Content Team MITRE Internal updated Description, Name