|
|
|
|
CWE-408 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 408 (Weakness Base) | | Description | Summary The software allows an entity to
perform a legitimate but expensive operation before
sufficient authentication or authorization has taken place. | | Observed Examples | | Reference | Description |
|---|
| CVE-2004-2458 | Tool creates directories before authenticating user. general class of issue? step
problem on product's side. |
| | Context Notes | Overlaps authentication errors. | | Relationships | | | Source Taxonomies | PLOVER - Early Amplification | | Applicable Platforms | All |
|