[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CWE
view XML

Privacy Violation

ID: 359Date: (C)2012-05-14   (M)2022-10-10
Type: weaknessStatus: INCOMPLETE
Abstraction Type: Class





Description

Mishandling private information, such as customer passwords or social security numbers, can compromise user privacy and is often illegal.

Applicable Platforms
Language Class: All

Time Of Introduction

  • Architecture and Design
  • Implementation
  • Operation

Related Attack Patterns

Common Consequences

ScopeTechnical ImpactNotes
Confidentiality
 
Read application data
 
 

Detection Methods
None

Potential Mitigations
None

Relationships

Related CWETypeViewChain
CWE-359 ChildOf CWE-907 Category CWE-888  

Demonstrative Examples   (Details)

  1. The following code contains a logging statement that tracks the contents of records added to a database by storing them in a log file. Among other values that are stored, the getPassword() function returns the user-supplied plaintext password associated with the account.

White Box Definitions
None

Black Box Definitions
None

Taxynomy Mappings

TaxynomyIdNameFit
7 Pernicious Kingdoms  Privacy Violation
 
 
CERT Java Secure Coding FIO13-J
 
Do not log sensitive information outside a trust boundary
 
 

References:

  1. J. Oates .AOL man pleads guilty to selling 92m email addies. The Register. Published on 2005.
  2. U.S. Department of Commerce .Safe Harbor Privacy Framework.
  3. Federal Trade Commission .Financial Privacy: The Gramm-Leach Bliley Act (GLBA).
  4. U.S. Department of Human Services .Health Insurance Portability and Accountability Act (HIPAA).
  5. Government of the State of California .California SB-1386. Published on 2002.
  6. Information Technology Laboratory, National Institute of Standards and Technology .SECURITY REQUIREMENTS FOR CRYPTOGRAPHIC MODULES. 2001-05-25.
CVE    4
CVE-2021-3980
CVE-2022-24719
CVE-2022-0155
CVE-2021-28559
...

© SecPod Technologies