CWE一覧に戻る
CWE-283

所有者不明

Unverified Ownership
脆弱性 レビュー中
JA

この製品は、重要なリソースが適切なエンティティによって所有されていることを適切に検証しません。

EN

The product does not properly verify that a critical resource is owned by the proper entity.

Scope: Access Control / Impact: Gain Privileges or Assume Identity
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
MITRE公式ページ — CWE-283