UI Discrepancy for Security Feature |
Weakness ID: 446 (Weakness Base) | Status: Incomplete |
Description Summary
The user interface does not correctly enable or configure a security feature, but the interface provides feedback that causes the user to believe that the feature is in a secure state.
Extended Description
When the user interface does not properly reflect what the user asks of it, then it can lead the user into a false sense of security. For example, the user might check a box to enable a security option to enable encrypted communications, but the software does not actually enable the encryption. Alternately, the user might provide a "restrict ALL'" access control rule, but the software only implements "restrict SOME".
Reference | Description |
---|---|
CVE-1999-1446 | UI inconsistency; visited URLs list not cleared when "Clear History" option is selected. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 445 | User Interface Errors | Development Concepts (primary)699 |
ChildOf | ![]() | 684 | Failure to Provide Specified Functionality | Research Concepts (primary)1000 |
ParentOf | ![]() | 447 | Unimplemented or Unsupported Feature in UI | Development Concepts (primary)699 Research Concepts1000 |
ParentOf | ![]() | 448 | Obsolete Feature in UI | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 449 | The UI Performs the Wrong Action | Development Concepts (primary)699 Research Concepts (primary)1000 |
This node is likely a loose composite that could be broken down into the different types of errors that cause the user interface to have incorrect interactions with the underlying security feature. |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Other Notes, Taxonomy Mappings, Type | ||||
2008-10-14 | CWE Content Team | MITRE | Internal | |
updated Description, Maintenance Notes, Other Notes | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-01-30 | User Interface Discrepancy for Security Feature | |||
2008-04-11 | User Interface Discrepancy for Security Feature | |||