|
|
|
|
CWE-424: Improper Protection of Alternate Path
| | Improper Protection of Alternate Path |
|
| Weakness ID: 424 (Weakness Class) | | Status: Draft |
Description
Description Summary The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Time of Introduction Common Consequences | Scope | Effect |
Access Control | Technical Impact: Bypass protection
mechanism; Gain privileges / assume
identity |
Potential Mitigations
Phase: Architecture and Design Deploy different layers of protection to implement security in
depth. |
Relationships Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| PLOVER | | | Alternate Path Errors |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| PLOVER | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Potential_Mitigations,
Time_of_Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships, Other_Notes,
Taxonomy_Mappings | | 2009-10-29 | CWE Content Team | MITRE | Internal | | updated Other_Notes | | 2010-12-13 | CWE Content Team | MITRE | Internal | | updated Name | | 2011-06-01 | CWE Content Team | MITRE | Internal | | updated Common_Consequences | | 2011-06-27 | CWE Content Team | MITRE | Internal | | updated Common_Consequences | | 2012-05-11 | CWE Content Team | MITRE | Internal | | updated Related_Attack_Patterns,
Relationships | | 2012-10-30 | CWE Content Team | MITRE | Internal | | updated Potential_Mitigations | | Previous Entry Names |
|---|
| Change Date | Previous Entry
Name |
|---|
| 2008-04-11 | Alternate Path
Errors | | | 2010-12-13 | Failure to Protect Alternate
Path | |
|