CWE-754 là gì?
Đang phân tích dữ liệu...
Đang phân tích dữ liệu...
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Từ chối dịch vụ: sập, thoát hoặc khởi động lại, Trạng thái ngoài dự kiến | Tính toàn vẹn, Tính sẵn sàng | The data which were produced as a result of a function call could be in a bad state upon return. If the return value is not checked, then this bad data may be used in operations, possibly leading to a crash or other unintended behaviors. |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tự động | Automated static analysis may be useful for detecting unusual conditions involving system resources or common programming idioms, but not for violations of business rules. | Khá |
| Phân tích động thủ công | Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the program under low memory conditions, run with insufficient privileges or permissions, interrupt a transaction before it is completed, or disable connectivity to basic network services such as DNS. Monitor the software for any unexpected behavior. If you trigger an unhandled exception or similar error that was discovered and handled by the application's environment, it may still indicate unexpected conditions that were not handled by the application itself. | — |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-754, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi