Information Loss or Omission |
Weakness ID: 221 (Weakness Class) | Status: Incomplete |
Description Summary
The software does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.
Extended Description
This can be resultant, e.g. a buffer overflow might trigger a crash before the product can log the event.
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 199 | Information Management Errors | Development Concepts (primary)699 |
ChildOf | ![]() | 664 | Improper Control of a Resource Through its Lifetime | Research Concepts (primary)1000 |
ParentOf | ![]() | 222 | Truncation of Security-relevant Information | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 223 | Omission of Security-relevant Information | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 224 | Obscured Security-relevant Information by Alternate Name | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 356 | Product UI does not Warn User of Unsafe Actions | Research Concepts (primary)1000 |
ParentOf | ![]() | 396 | Declaration of Catch for Generic Exception | Research Concepts1000 |
ParentOf | ![]() | 397 | Declaration of Throws for Generic Exception | Research Concepts1000 |
ParentOf | ![]() | 451 | UI Misrepresentation of Critical Information | Research Concepts (primary)1000 |
CAPEC-ID | Attack Pattern Name | (CAPEC Version: 1.4) |
---|---|---|
81 | Web Logs Tampering |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Description, Relationships, Taxonomy Mappings |