CWE-345: Insufficient Verification of Data Authenticity
Insufficient Verification of Data Authenticity
Weakness ID: 345 (Weakness Class) Status: Draft
Description
Description Summary
The software does not sufficiently verify the origin or
authenticity of data, in a way that causes it to accept invalid
data.
Time of Introduction
Architecture and Design
Implementation
Relationships
Relationship Notes
"origin validation" could fall under this.
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Insufficient Verification of Data
OWASP Top Ten 2004 A3 CWE More Specific Broken Authentication and Session
Management
Maintenance Notes
The specific ways in which the origin is not properly identified should be
laid out as separate weaknesses. In some sense, this is more like a
category.
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Maintenance Notes, Relationships,
Relationship Notes, Taxonomy Mappings 2009-05-27 CWE Content Team MITRE Internal updated Related Attack Patterns 2009-07-27 CWE Content Team MITRE Internal updated Related Attack Patterns Previous Entry Names Change Date Previous Entry
Name 2008-04-11 Insufficient Verification of
Data