CQE-9152: Unauthorized Access to Sensitive Information

 
Unauthorized Access to Sensitive Information
[an error occurred while processing this directive] Definition in a New Window Definition in a New Window
Consequence ID: 9152 Maturity: Preliminary
+ Description

Description Summary

Unauthorized Access to Sensitive Information may result when improper access controls are implemented, resulting in data leaks or unauthorized parties accessing information.
+ Relationships
NatureTypeIDNameView(s) this relationship pertains to
View
CanFollow
Is
Issue
22Path Traversal Improper Input Neutralization
Default Graph (primary)9001
CanFollow
Is
Issue
79Cross-site Scripting Improper Input Neutralization
Default Graph (primary)9001
CanFollow
Is
Issue
89SQL Injection Improper Input Neutralization
Default Graph (primary)9001
CanFollow
Is
Issue
99Name or Reference Resolution Improper Input Neutralization
Default Graph (primary)9001
CanFollow
Is
Issue
120Buffer Copy without Checking Size of Input
Default Graph (primary)9001
CanFollow
Is
Issue
129Array Index Improper Input Neutralization
Default Graph (primary)9001
CanFollow
Is
Issue
327Broken or Risky Cryptographic Algorithm Usage
Default Graph (primary)9001
CanFollow
Is
Issue
672Expired or Released Resource Usage
Default Graph (primary)9001
CanFollow
Is
Issue
772Missing Release of Resource after Effective Lifetime
Default Graph (primary)9001
CanFollow
Is
Issue
789Uncontrolled Memory Allocation
Default Graph (primary)9001
CanFollow
Is
Issue
798Hard-Coded Credentials Usage for Remote Authentication
Default Graph (primary)9001
CanFollow
Pr
Practice
9003SQL Command Execution
Default Graph (primary)9001
CanFollow
Pr
Practice
9006OS Command Execution
Default Graph (primary)9001
CanFollow
Pr
Practice
9049Array Indexing
Default Graph (primary)9001
CanFollow
Pr
Practice
9063Authentication Practices
Default Graph (primary)9001
CanFollow
Pr
Practice
9078Memory Management
Default Graph (primary)9001
CanFollow
Pr
Practice
9097Output Generation
Default Graph (primary)9001
CanFollow
Pr
Practice
9127Resource Identification Control
Default Graph (primary)9001
CanFollow
Pr
Practice
9136Cryptography
Default Graph (primary)9001
CanFollow
Pr
Practice
9183File Path Control
Default Graph (primary)9001
Page Last Updated or Reviewed: October 01, 2017