|
Category ID: 859
Vulnerability Mapping:
PROHIBITED
This CWE ID must not be used to map to real-world vulnerabilities
|
| Nature | Type | ID | Name |
|---|---|---|---|
| MemberOf | 844 | Weaknesses Addressed by The CERT Oracle Secure Coding Standard for Java (2011) | |
| HasMember | 111 | Direct Use of Unsafe JNI | |
| HasMember | 266 | Incorrect Privilege Assignment | |
| HasMember | 272 | Least Privilege Violation | |
| HasMember | 300 | Channel Accessible by Non-Endpoint | |
| HasMember | 302 | Authentication Bypass by Assumed-Immutable Data | |
| HasMember | 319 | Cleartext Transmission of Sensitive Information | |
| HasMember | 347 | Improper Verification of Cryptographic Signature | |
| HasMember | 470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | |
| HasMember | 494 | Download of Code Without Integrity Check | |
| HasMember | 732 | Incorrect Permission Assignment for Critical Resource | |
| HasMember | 807 | Reliance on Untrusted Inputs in a Security Decision |
|
Usage: PROHIBITED
(this CWE ID must not be used to map to real-world vulnerabilities)
|
|
Reason: Category |
|
Rationale: This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. |
|
Comments: See member weaknesses of this category. |
|
[REF-813] Fred Long, Dhruv Mohindra, Robert C. Seacord, Dean F. Sutherland and David Svoboda. "The CERT Oracle Coding Standard for Java". 1st Edition. Addison-Wesley Professional. 2011-09-18.
|
|
Use of the Common Weakness Enumeration (CWE™) and the associated references from this website are subject to the Terms of Use. CWE is sponsored by the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and managed by the Homeland Security Systems Engineering and Development Institute (HSSEDI) which is operated by The MITRE Corporation (MITRE). Copyright © 2006–2026, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation. |
||

