CWE-288

CWE-288 là gì?

Đang phân tích dữ liệu...

Thống kê dữ liệu

THỨ HẠNG OWASP TOP 10:20257 — A07:2025 — Authentication Failures
TỔNG SỐ CVE LIÊN QUAN (365 NGÀY)144
MỨC TRỪU TƯỢNGCơ bản

Số lượng lỗ hổng nằm trong CWE-288

144 lỗ hổngTăng 152,6% so với cùng kỳ

Số lượng lỗ hổng trong CISA KEV của CWE-288

5 lỗ hổngTăng 25% so với cùng kỳ

Định nghĩa chính thức

TheoMitre CWE

Đặc điểm

Dữ liệu MITRE CWE chính thức

Giai đoạn hình thành

  • Kiến trúc và thiết kế: COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.
  • Kiến trúc và thiết kế: This is often seen in web applications that assume that access to a particular CGI program can only be obtained through a "front" screen, when the supporting programs are directly accessible. But this problem is not just in web apps.

Hậu quả thường gặp

Dữ liệu MITRE CWE chính thức
Tác độngPhạm viDiễn giải
Vượt qua cơ chế bảo vệKiểm soát truy cập—

Biện pháp giảm thiểu rủi ro

Dữ liệu MITRE CWE chính thức
  1. Kiến trúc và thiết kếFunnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.

Lỗ hổng điển hình

Nguồn (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan