|
|
|
|
CWE-408: Incorrect Behavior Order: Early Amplification | |
| | Incorrect Behavior Order: Early Amplification |
|
| Weakness ID: 408 (Weakness Base) | | Status: Draft |
Description
Description Summary The software allows an entity to perform a legitimate but
expensive operation before authentication or authorization has taken
place.
Time of Introduction
- Architecture and Design
- Implementation
Observed Examples | Reference | Description |
| CVE-2004-2458 | Tool creates directories before authenticating
user. general class of issue? step problem on product's
side. |
Other Notes
|
Overlaps authentication errors.
|
Relationships Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| PLOVER | | | Early Amplification |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| PLOVER | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Time of Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships, Other Notes,
Taxonomy Mappings | | 2009-05-27 | CWE Content Team | MITRE | Internal | | updated Description |
|