CWE-347 là gì?
Chưa thể hoàn tất phân tích. Vui lòng thử lại.
Chưa thể hoàn tất phân tích. Vui lòng thử lại.
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Chiếm đặc quyền hoặc mạo danh, Thay đổi dữ liệu ứng dụng, Thực thi mã hoặc lệnh trái phép | Kiểm soát truy cập, Tính toàn vẹn, Tính bí mật | An attacker could gain access to sensitive data and possibly execute unauthorized code. |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tự động | Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) | Cao |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-347, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi