CWE
Home > CWE List > VIEW SLICE: CWE-604: Deprecated Entries (1.6)  

CWE-604: Deprecated Entries

 
Deprecated Entries
Definition in a New Window Definition in a New Window
View ID: 604 (View: Implicit Slice)Status: Draft
+ View Data

View Objective

CWE nodes in this view (slice) have been deprecated. There should be a reference pointing to the replacement in each deprecated weakness.

View Filter: .//@Status='Deprecated'

+ View Metrics
CWEs in this viewTotal CWEs
Total11out of791
Views0out of22
Categories1out of106
Weaknesses10out of651
Compound_Elements0out of12
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships, View Structure
2008-11-24CWE Content TeamMITREInternal
updated Name, Relationships
2009-05-27CWE Content TeamMITREInternal
updated Relationships
2009-07-27CWE Content TeamMITREInternal
updated Relationships
2009-08-28CWE Content TeamMITREInternal
changed explicit member list to implicit filter
2009-10-29CWE Content TeamMITREInternal
updated Relationships, View Filter, View Structure
View Components
View Components
A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
 
DEPRECATED (Duplicate): Covert Timing Channel
Definition in a New Window Definition in a New Window
Weakness ID: 516 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness can be found at CWE-385.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED (Duplicate): Failure to provide confidentiality for stored data
Definition in a New Window Definition in a New Window
Weakness ID: 218 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Alternate Terms, Applicable Platforms, Common Consequences, Description, Likelihood of Exploit, Name, Relationships, Type
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED (Duplicate): General Information Management Problems
Definition in a New Window Definition in a New Window
Weakness ID: 225 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness can be found at CWE-199.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED (Duplicate): HTTP response splitting
Definition in a New Window Definition in a New Window
Weakness ID: 443 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness can be found at CWE-113.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED (Duplicate): Miscalculated Null Termination
Definition in a New Window Definition in a New Window
Weakness ID: 132 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This entry has been deprecated because it was a duplicate of CWE-170. All content has been transferred to CWE-170.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Applicable Platforms, Causal Nature, Common Consequences, Description, Likelihood of Exploit, Name, Relationships, Type
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED (Duplicate): Proxied Trusted Channel
Definition in a New Window Definition in a New Window
Weakness ID: 423 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441.
+ Content History
Submissions
Submission DateSubmitterOrganizationSource
PLOVERExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Potential Mitigations, Time of Introduction
2008-09-08CWE Content TeamMITREInternal
updated Relationships, Other Notes, Taxonomy Mappings
2008-11-05CWE Content TeamMITREInternal
deprecated this entry as a duplicate of 441
2008-11-24CWE Content TeamMITREInternal
updated Applicable Platforms, Description, Name, Other Notes, Potential Mitigations, Relationships, Taxonomy Mappings, Time of Introduction, Type
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED: Failure to Protect Stored Data from Modification
Definition in a New Window Definition in a New Window
Weakness ID: 217 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness has been deprecated because it incorporated and confused multiple weaknesses. The issues formerly covered in this weakness can be found at CWE-766 and CWE-767.
+ Content History
Submissions
Submission DateSubmitterOrganizationSource
CLASPExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Time of Introduction
2008-09-08CWE Content TeamMITREInternal
updated Common Consequences, Relationships, Other Notes, Taxonomy Mappings
2009-05-20CWE Content TeamMITREInternal
deprecated this entry in favor of new entries which focus on the multiple weaknesses formerly described here, CWE-766 and CWE-767
2009-05-27CWE Content TeamMITREInternal
updated Alternate Terms, Applicable Platforms, Common Consequences, Demonstrative Examples, Description, Likelihood of Exploit, Name, Other Notes, Potential Mitigations, Related Attack Patterns, Relationships, Taxonomy Mappings, Time of Introduction, Type
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED: General Special Element Problems
Definition in a New Window Definition in a New Window
Category ID: 139 (Deprecated Category)Status: Deprecated
+ Description

Description Summary

This entry has been deprecated. It is a leftover from PLOVER, but CWE-138 (Failure to Sanitize Special Elements) is a more appropriate mapping.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Applicable Platforms, Description, Functional Areas, Name, Relationships, Type
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED: Improper Sanitization of Custom Special Characters
Definition in a New Window Definition in a New Window
Weakness ID: 92 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

The software uses a custom or proprietary language or representation, but when it receives input from an upstream component, it does not sanitize or incorrectly sanitizes special elements when they are sent to a downstream component.

Extended Description

This allows attackers to modify the syntax, content, or commands before they are processed by a downstream component.

+ Maintenance Notes

This and some other CWE entries were distinct in PLOVER but effectively have overlap in CWE. PLOVER sometimes defined "other" and "miscellaneous" categories in order to satisfy exhaustiveness requirements for taxonomies. Within the context of CWE, the use of a more abstract entry is preferred in mapping situations.

+ Content History
Submissions
Submission DateSubmitterOrganizationSource
PLOVERExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Time of Introduction
2008-09-08CWE Content TeamMITREInternal
updated Maintenance Notes, Relationships, Relationship Notes, Taxonomy Mappings, Weakness Ordinalities
2008-10-14CWE Content TeamMITREInternal
updated Description, Name
2009-05-27CWE Content TeamMITREInternal
updated Description, Name
2009-07-27CWE Content TeamMITREInternal
updated Applicable Platforms, Causal Nature, Maintenance Notes, Name, Observed Examples, Potential Mitigations, Related Attack Patterns, Relationship Notes, Relationships, Research Gaps, Taxonomy Mappings, Time of Introduction, Type, Weakness Ordinalities
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED: Incorrect Initialization
Definition in a New Window Definition in a New Window
Weakness ID: 458 (Deprecated Weakness Base)Status: Deprecated
+ Description

Description Summary

This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to CWE-665 for the more abstract problem.
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships
2009-10-29CWE Content TeamMITREInternal
updated Relationships
 
DEPRECATED: Often Misused: Path Manipulation
Definition in a New Window Definition in a New Window
Weakness ID: 249 (Deprecated Weakness Variant)Status: Deprecated
+ Description

Description Summary

This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.
+ Maintenance Notes

This entry was deprecated for several reasons. The primary reason is over-loading of the "path manipulation" term and the description. The original description for this entry was the same as that for the "Often Misused: File System" item in the original Seven Pernicious Kingdoms paper. However, Seven Pernicious Kingdoms also has a "Path Manipulation" phrase that is for external control of pathnames (CWE-73), which is a factor in symbolic link following and path traversal, neither of which is explicitly mentioned in 7PK. Fortify uses the phrase "Often Misused: Path Manipulation" for a broader range of problems, generally for issues related to buffer management. Given the multiple conflicting uses of this term, there is a chance that CWE users may have incorrectly mapped to this entry.

The second reason for deprecation is an implied combination of multiple weaknesses within buffer-handling functions. The focus of this entry has generally been on the path-conversion functions and their association with buffer overflows. However, some of Fortify's Vulncat entries have the term "path manipulation" but describe a non-overflow weakness in which the buffer is not guaranteed to contain the entire pathname, i.e., there is information truncation (see CWE-222 for a similar concept). A new entry for this non-overflow weakness may be created in a future version of CWE.

+ Content History
Submissions
Submission DateSubmitterOrganizationSource
7 Pernicious KingdomsExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Time of Introduction
2008-08-01KDM AnalyticsExternal
added/updated white box definitions
2008-09-08CWE Content TeamMITREInternal
updated Applicable Platforms, Relationships, Other Notes, Taxonomy Mappings
2009-05-27CWE Content TeamMITREInternal
updated Demonstrative Examples
2009-07-17
(Critical)
KDM AnalyticsExternal
Described inconsistencies in this entry, which the CWE Content Team had already slated for deprecation.
2009-07-27CWE Content TeamMITREInternal
updated Affected Resources, Applicable Platforms, Demonstrative Examples, Description, Maintenance Notes, Name, Other Notes, Potential Mitigations, Relationships, Taxonomy Mappings, Time of Introduction, Type, White Box Definitions
2009-10-29CWE Content TeamMITREInternal
updated Relationships
Page Last Updated: October 29, 2009