CWE
Home > CWE List > CWE-408 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-408 Individual Dictionary Definition (Draft 9)

Incorrect Behavior Order: Early Amplification
Weakness ID
Status: Draft

408 (Weakness Base)

Description

Summary

The software allows an entity to perform a legitimate but expensive operation before sufficient authentication or authorization has taken place.

Observed Examples
ReferenceDescription
CVE-2004-2458Tool creates directories before authenticating user. general class of issue? step problem on product's side.
Context Notes

Overlaps authentication errors.

Relationships
NatureTypeIDName
ChildOfWeakness ClassWeakness ClassWeakness Class405Asymmetric Resource Consumption (Amplification)
Source Taxonomies

PLOVER - Early Amplification

Applicable Platforms

All

Page Last Updated: April 22, 2008