...
CWE ID | CWE name/description | Parasoft rule ID(s) |
---|---|---|
CWE-617 | Reachable Assertion |
|
CWE-427 | Uncontrolled Search Path Element |
|
CWE-611 | Improper Restriction of XML External Entity Reference |
|
CWE-770 | Allocation of Resources Without Limits or Throttling |
|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor |
|
CWE-732 | Incorrect Permission Assignment for Critical Resource |
|
CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') |
|
CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
|
CWE-295 | Improper Certificate Validation |
|
CWE-522 | Insufficiently Protected Credentials |
|
CWE-401 | Missing Release of Memory after Effective Lifetime |
|
CWE-400 | Uncontrolled Resource Consumption |
|
CWE-639 | Authorization Bypass Through User-Controlled Key |
|
CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
|
CWE-668 | Exposure of Resource to Wrong Sphere |
|
CWE
...
CWE ID
...
CWE name/description
...
Parasoft rule ID(s)
...
CWE-787
...
Out-of-bounds Write
...
- CWE.787.ARRAY
...
CWE-79
...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
...
- CWE.79.VPPD
- CWE.79.TDRESP
- CWE.79.TDXSS
- CWE.79.AXSSE
- CWE.79.CSP
...
CWE-89
...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
...
- CWE.89.TDSQL
- CWE.89.TDSQLC
...
CWE-20
...
Improper Input Validation
...
- CWE.20.ARRAY
- CWE.20.VPPD
- CWE.20.TDNET
- CWE.20.TDFNAMES
- CWE.20.TDCMD
- CWE.20.TDRESP
- CWE.20.TDXSS
- CWE.20.TDSQL
- CWE.20.TDSQLC
...
CWE-125
...
Out-of-bounds Read
...
- CWE.125.ARRAY
...
CWE-78
...
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
...
- CWE.78.TDCMD
...
CWE-416
...
Use After Free
...
- CWE.416.DISP
- CWE.416.FIN
...
CWE-22
...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
...
- CWE.22.TDFNAMES
...
CWE-352
...
Cross-Site Request Forgery (CSRF)
...
- CWE.352.VPPD
- CWE.352.TDRESP
- CWE.352.VAFT
- CWE.352.CA3147
- CWE.352.CA5391
...
CWE-434
...
Unrestricted Upload of File with Dangerous Type
...
- CWE.434.TDFNAMES
...
CWE-476
...
NULL Pointer Dereference
...
- CWE.476.NR
- CWE.476.DEREF
- CWE.476.CNFA
...
CWE-502
...
Deserialization of Untrusted Data
...
- CWE.502.IIDC
- CWE.502.UIS
- CWE.502.IDC
- CWE.502.MGODWSPA
- CWE.502.CA2350
- CWE.502.CA2351
- CWE.502.CA2352
- CWE.502.CA2353
- CWE.502.CA2354
- CWE.502.CA2355
- CWE.502.CA2356
- CWE.502.CA2361
- CWE.502.CA2362
...
CWE-190
...
Integer Overflow or Wraparound
...
- CWE.190.AIWIL
- CWE.190.AIOAC
- CWE.190.INTOVERF
...
CWE-287
...
Improper Authentication
...
- CWE.287.TDPASSWD
- CWE.287.AAM
- CWE.287.UAAMC
- CWE.287.LUAFLA
- CWE.287.IIPHEU
- CWE.287.CA5359
- CWE.287.CA5403
- CWE.287.CA5376
- CWE.287.CA5390
...
CWE-798
...
Use of Hard-coded Credentials
...
- CWE.798.HARDCONN
- CWE.798.HPW
- CWE.798.CA5403
...
CWE-862
...
Missing Authorization
...
- CWE.862.UAA
...
CWE-77
...
Improper Neutralization of Special Elements used in a Command ('Command Injection')
...
- CWE.77.TDCMD
...
CWE-306
...
Missing Authentication for Critical Function
...
- N/A
...
CWE-119
...
Improper Restriction of Operations within the Bounds of a Memory Buffer
...
- CWE.119.ARRAY
...
CWE-276
...
Incorrect Default Permissions
...
- N/A
...
CWE-918
...
Server-Side Request Forgery (SSRF)
...
- CWE.918.TDNET
- CWE.918.CA3147
- CWE.918.CA5368
- CWE.918.CA5391
- CWE.918.CA5395
...
CWE-362
...
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
...
- CWE.362.LOCKSETGET
- CWE.362.DIFCS
...
CWE-400
...
Uncontrolled Resource Consumption
...
- CWE.400.LEAKS
- CWE.400.TDLOG
- CWE.400.CA5362
...
CWE-611
...
Improper Restriction of XML External Entity Reference
...
- CWE.611.PDTDP
- CWE.611.USXRS
- CWE.611.CA3061
- CWE.611.CA3075
- CWE.611.CA3077
- CWE.611.CA5366
- CWE.611.CA5369
- CWE.611.CA5370
- CWE.611.CA5371
- CWE.611.CA5372
...
CWE-94
...
Improper Control of Generation of Code ('Code Injection')
...
- CWE.94.TDCODE
CWE Weaknesses On the Cusp 2022 Mapping
...
CWE ID
...
CWE name/description
...
Parasoft rule ID(s)
...
CWE-295
...
Improper Certificate Validation
...
- CWE.295.TDCODE
...
CWE-427
...
Uncontrolled Search Path Element
...
- CWE.427.DNICV
- CWE.427.CA5359
- CWE.427.CA5403
...
CWE-863
...
Incorrect Authorization
...
- CWE.863.CA5393
...
CWE-269
...
Improper Privilege Management
...
- CWE.269.AAM
- CWE.269.UAAMC
- CWE.269.AUTH
...
CWE-732
...
Incorrect Permission Assignment for Critical Resource
...
- CWE.732.IDENTITY
- CWE.732.CA5375
- CWE.732.CA5377
...
CWE-843
...
Access of Resource Using Incompatible Type ('Type Confusion')
...
- CWE.843.ADSVSP
- CWE.843.CA5396
...
CWE-668
...
Exposure of Resource to Wrong Sphere
...
- N/A
...
CWE-200
...
Exposure of Sensitive Information to an Unauthorized Actor
...
- N/A
...
CWE-1321
...
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
...
- CWE.1321.SDE
- CWE.1321.SENS
- CWE.1321.PEO
- CWE.1321.ACPST
- CWE.1321.CSG
- CWE.1321.SENSLOG
- CWE.1321.CA3004
...
CWE-601
...
URL Redirection to Untrusted Site ('Open Redirect')
...
- N/A
...
CWE-401
...
Missing Release of Memory after Effective Lifetime
...
- CWE.401.TDNET
- CWE.401.TDRESP
...
CWE-59
...
Improper Link Resolution Before File Access ('Link Following')
...
- N/A
...
CWE-522
...
Insufficiently Protected Credentials
...
- CWE.522.VLT
...
CWE-319
...
Cleartext Transmission of Sensitive Information
...
- CWE.319.TDPASSWD
...
CWE-312
...
Cleartext Storage of Sensitive Information
...
- N/A
CWE 4.15 Mapping4.15 Mapping
CWE ID | CWE name/description | Parasoft rule ID(s) |
---|---|---|
CWE-20 | Improper Input Validation |
|
CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|
CWE-64 | Windows Shortcut Following (.LNK) |
|
CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
|
CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
|
CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
|
CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') |
|
CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
|
CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') |
|
CWE-95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') |
|
CWE-99 | Improper Control of Resource Identifiers ('Resource Injection') |
|
CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') |
|
CWE-125 | Out-of-bounds Read |
|
CWE-129 | Improper Validation of Array Index |
|
CWE-131 | Incorrect Calculation of Buffer Size |
|
CWE-134 | Use of Externally-Controlled Format String |
|
CWE-190 | Integer Overflow or Wraparound |
|
CWE-191 | Integer Underflow (Wrap or Wraparound) |
|
CWE-197 | Numeric Truncation Error |
|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor |
|
CWE-201 | Insertion of Sensitive Information Into Sent Data |
|
CWE-209 | Generation of Error Message Containing Sensitive Information |
|
CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer |
|
CWE-250 | Execution with Unnecessary Privileges |
|
CWE-252 | Unchecked Return Value |
|
CWE-256 | Plaintext Storage of a Password |
|
CWE-259 | Use of Hard-coded Password |
|
CWE-260 | Password in Configuration File |
|
CWE-269 | Improper Privilege Management |
|
CWE-287 | Improper Authentication |
|
CWE-294 | Authentication Bypass by Capture-replay |
|
CWE-295 | Improper Certificate Validation |
|
CWE-299 | Improper Check for Certificate Revocation |
|
CWE-307 | Improper Restriction of Excessive Authentication Attempts |
|
CWE-311 | Missing Encryption of Sensitive Data |
|
CWE-316 | Cleartext Storage of Sensitive Information in Memory |
|
CWE-319 | Cleartext Transmission of Sensitive Information |
|
CWE-321 | Use of Hard-coded Cryptographic Key |
|
CWE-326 | Inadequate Encryption Strength |
|
CWE-327 | Use of a Broken or Risky Cryptographic Algorithm |
|
CWE-328 | Use of Weak Hash |
|
CWE-329 | Generation of Predictable IV with CBC Mode |
|
CWE-338 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
|
CWE-350 | Reliance on Reverse DNS Resolution for a Security-Critical Action |
|
CWE-352 | Cross-Site Request Forgery (CSRF) |
|
CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
|
CWE-369 | Divide By Zero |
|
CWE-391 | Unchecked Error Condition |
|
CWE-395 | Use of NullPointerException Catch to Detect NULL Pointer Dereference |
|
CWE-396 | Declaration of Catch for Generic Exception |
|
CWE-397 | Declaration of Throws for Generic Exception |
|
CWE-400 | Uncontrolled Resource Consumption |
|
CWE-402 | Transmission of Private Resources into a New Sphere ('Resource Leak') |
|
CWE-412 | Unrestricted Externally Accessible Lock |
|
CWE-416 | Use After Free |
|
CWE-426 | Untrusted Search Path |
|
CWE-427 | Uncontrolled Search Path Element |
|
CWE-434 | Unrestricted Upload of File with Dangerous Type |
|
CWE-456 | Missing Initialization of a Variable |
|
CWE-457 | Use of Uninitialized Variable |
|
CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') |
|
CWE-472 | External Control of Assumed-Immutable Web Parameter |
|
CWE-476 | NULL Pointer Dereference |
|
CWE-480 | Use of Incorrect Operator |
|
CWE-481 | Assigning instead of Comparing |
|
CWE-494 | Download of Code Without Integrity Check |
|
CWE-499 | Serializable Class Containing Sensitive Data |
|
CWE-502 | Deserialization of Untrusted Data |
|
CWE-521 | Weak Password Requirements |
|
CWE-532 | Insertion of Sensitive Information into Log File |
|
CWE-546 | Suspicious Comment |
|
CWE-554 | ASP.NET Misconfiguration: Not Using Input Validation Framework |
|
CWE-561 | Dead Code |
|
CWE-563 | Assignment to Variable without Use |
|
CWE-570 | Expression is Always False |
|
CWE-571 | Expression is Always True |
|
CWE-595 | Comparison of Object References Instead of Object Contents |
|
CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') |
|
CWE-611 | Improper Restriction of XML External Entity Reference |
|
CWE-613 | Insufficient Session Expiration |
|
CWE-614 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute |
|
CWE-617 | Reachable Assertion |
|
CWE-624 | Executable Regular Expression Error |
|
CWE-638 | Not Using Complete Mediation |
|
CWE-643 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') |
|
CWE-662 | Improper Synchronization |
|
CWE-676 | Use of Potentially Dangerous Function |
|
CWE-681 | Incorrect Conversion between Numeric Types |
|
CWE-732 | Incorrect Permission Assignment for Critical Resource |
|
CWE-759 | Use of a One-Way Hash without a Salt |
|
CWE-760 | Use of a One-Way Hash with a Predictable Salt |
|
CWE-770 | Allocation of Resources Without Limits or Throttling |
|
CWE-771 | Missing Reference to Active Allocated Resource |
|
CWE-772 | Missing Release of Resource after Effective Lifetime |
|
CWE-778 | Insufficient Logging |
|
CWE-779 | Logging of Excessive Data |
|
CWE-780 | Use of RSA Algorithm without OAEP |
|
CWE-787 | Out-of-bounds Write |
|
CWE-789 | Memory Allocation with Excessive Size Value |
|
CWE-798 | Use of Hard-coded Credentials |
|
CWE-807 | Reliance on Untrusted Inputs in a Security Decision |
|
CWE-827 | Improper Control of Document Type Definition |
|
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere |
|
CWE-833 | Deadlock |
|
CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') |
|
CWE-838 | Inappropriate Encoding for Output Context |
|
CWE-862 | Missing Authorization |
|
CWE-863 | Incorrect Authorization |
|
CWE-918 | Server-Side Request Forgery (SSRF) |
|
CWE-1004 | Sensitive Cookie Without 'HttpOnly' Flag |
|
CWE-1386 | Insecure Operation on Windows Junction / Mount Point |
|