CWE-276 là gì?
Đang phân tích dữ liệu...
Đang phân tích dữ liệu...
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Đọc dữ liệu ứng dụng, Thay đổi dữ liệu ứng dụng | Tính bí mật, Tính toàn vẹn | — |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tệp nhị phân hoặc bytecode tự động | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Inter-application Flow Analysis | SOAR một phần |
| Phân tích tĩnh tệp nhị phân hoặc bytecode thủ công | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies | SOAR một phần |
| Phân tích động với diễn giải kết quả tự động | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Host-based Vulnerability Scanners - Examine configuration for flaws, verifying that audit mechanisms work, ensure host configuration meets certain predefined criteria Web Application Scanner Web Services Scanner Database Scanners | SOAR một phần |
| Phân tích động với diễn giải kết quả thủ công | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Host Application Interface Scanner ``` Cost effective for partial coverage: ``` Fuzz Tester Framework-based Fuzzer Automated Monitored Execution Forced Path Execution | Cao |
| Phân tích tĩnh mã nguồn thủ công | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Manual Source Code Review (not inspections) ``` Cost effective for partial coverage: ``` Focused Manual Spotcheck - Focused manual analysis of source | Cao |
| Phân tích tĩnh mã nguồn tự động | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Context-configured Source Code Weakness Analyzer | SOAR một phần |
| Phân tích tĩnh tự động | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Configuration Checker | SOAR một phần |
| Rà soát kiến trúc hoặc thiết kế | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Formal Methods / Correct-By-Construction ``` Cost effective for partial coverage: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.) | Cao |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-276, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi