CWE一覧に戻る
CWE-1023

因子が欠落した不完全な比較

Incomplete Comparison with Missing Factors
脆弱性 作成中
JA

この製品は、各企業の複数の要因または特性を考慮しなければならない企業間の比較を実行するが、比較にはこれらの要因の1つまたは複数が含まれていない。

EN

The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.

Scope: Integrity, Access Control / Impact: Alter Execution Logic; Bypass Protection Mechanism
Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.
MITRE公式ページ — CWE-1023