CWE-5 J2EE误配置:未经加密的数据传输

J2EE Misconfiguration: Data Transmission Without Encryption

结构: Simple

Abstraction: Variant

状态: Draft

被利用可能性: unkown

基本描述

Information sent over a network can be compromised while in transit. An attacker may be able to read or modify the contents if the data are sent in plaintext or are weakly encrypted.

相关缺陷

  • cwe_Nature: ChildOf cwe_CWE_ID: 319 cwe_View_ID: 1000 cwe_Ordinal: Primary

适用平台

Language: {'cwe_Name': 'Java', 'cwe_Prevalence': 'Undetermined'}

常见的影响

范围 影响 注释
Confidentiality Read Application Data
Integrity Modify Application Data

可能的缓解方案

System Configuration

策略:

The application configuration should ensure that SSL or an encryption mechanism of equivalent strength and vetted reputation is used for all access-controlled pages.

Notes

分类映射

映射的分类名 ImNode ID Fit Mapped Node Name
7 Pernicious Kingdoms J2EE Misconfiguration: Insecure Transport