CWE-610: Externally Controlled Reference to a Resource in Another Sphere
Abstraction | Structure | Status |
---|
None | Simple | Draft |
Description
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Nature | ID | View ID | Name |
---|
ChildOf | CWE-664 | 1000 | Improper Control of a Resource Through its Lifetime |
Modes of Introduction
Phase | Note |
---|
Architecture and Design | COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic. |
Common Consequences
Scope | Impact | Note |
---|
Confidentiality, Integrity | Read Application Data, Modify Application Data | |