Skip to content

CWE-610: Externally Controlled Reference to a Resource in Another Sphere

AbstractionStructureStatus
NoneSimpleDraft

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

NatureIDView IDName
ChildOfCWE-6641000Improper Control of a Resource Through its Lifetime

Modes of Introduction

PhaseNote
Architecture and DesignCOMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.

Common Consequences

ScopeImpactNote
Confidentiality, IntegrityRead Application Data, Modify Application Data