CWE-200

CWE-200 là gì?

Đang phân tích dữ liệu...

Thống kê dữ liệu

THỨ HẠNG OWASP TOP 10:20251 — A01:2025 — Broken Access Control
TỔNG SỐ CVE LIÊN QUAN (365 NGÀY)967
MỨC TRỪU TƯỢNGLớp
KHẢ NĂNG KHAI THÁCCao

Số lượng lỗ hổng nằm trong CWE-200

967 lỗ hổngTăng 282,2% so với cùng kỳ

Số lượng lỗ hổng trong CISA KEV của CWE-200

2 lỗ hổngTăng 100% so với cùng kỳ

Định nghĩa chính thức

TheoMitre CWE

Đặc điểm

Dữ liệu MITRE CWE chính thức

Tên gọi khác

  • Information Disclosure — This term is frequently used in vulnerability advisories to describe a consequence or technical impact, for any vulnerability that has a loss of confidentiality. Often, CWE-200 can be misused to represent the loss of confidentiality, even when the mistake - i.e., the weakness - is not directly related to the mishandling of the information itself, such as an out-of-bounds read that accesses sensitive memory contents; here, the out-of-bounds read is the primary weakness, not the disclosure of the memory. In addition, this phrase is also used frequently in policies and legal documents, but it does not refer to any disclosure of security-relevant information.
  • Information Leak — This is a frequently used term, however the "leak" term has multiple uses within security. In some cases it deals with the accidental exposure of information from a different weakness, but in other cases (such as "memory leak"), this deals with improper tracking of resources, which can lead to exhaustion. As a result, CWE is actively avoiding usage of the "leak" term.

Giai đoạn hình thành

  • Kiến trúc và thiết kế
  • Hiện thực hóa

Hậu quả thường gặp

Dữ liệu MITRE CWE chính thức
Tác độngPhạm viDiễn giải
Đọc dữ liệu ứng dụngTính bí mật—

Biện pháp giảm thiểu rủi ro

Dữ liệu MITRE CWE chính thức
  1. Phân tách đặc quyền · Kiến trúc và thiết kếCompartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

Cách phát hiện trong hệ thống

Dữ liệu MITRE CWE chính thức
Phương phápCách làmHiệu quả
Phân tích tĩnh tệp nhị phân hoặc bytecode tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Bytecode Weakness Analysis - including disassembler + source code weakness analysis Inter-application Flow AnalysisSOAR một phần
Phân tích động với diễn giải kết quả tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Web Application Scanner Web Services Scanner Database ScannersCao
Phân tích động với diễn giải kết quả thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Fuzz Tester Framework-based Fuzzer Automated Monitored Execution Monitored Virtual Environment - run potentially malicious code in sandbox / wrapper / virtual machine, see if it does anything suspiciousSOAR một phần
Phân tích tĩnh mã nguồn thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Manual Source Code Review (not inspections)Cao
Phân tích tĩnh mã nguồn tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Context-configured Source Code Weakness Analyzer ``` Cost effective for partial coverage: ``` Source code Weakness AnalyzerCao
Rà soát kiến trúc hoặc thiết kếAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Formal Methods / Correct-By-Construction ``` Cost effective for partial coverage: ``` Attack Modeling Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)Cao

Lỗ hổng điển hình

Dữ liệu MITRE CWE chính thức

Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-200, dựa theo mức độ ưu tiên

Nguồn (5)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan