Skip to content

CWE-706: Use of Incorrectly-Resolved Name or Reference

AbstractionStructureStatus
NoneSimpleIncomplete

Description

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

NatureIDView IDName
ChildOfCWE-6641000Improper Control of a Resource Through its Lifetime
PeerOfCWE-991000Improper Control of Resource Identifiers (‘Resource Injection’)

Modes of Introduction

PhaseNote
Architecture and Design-
Implementation-

Applicable Platforms

Languages

Class: Not Language-Specific

Technologies

Common Consequences

ScopeImpactNote
Confidentiality, IntegrityRead Application Data, Modify Application Data