COMMON WEAKNESS ENUMERATIONIncomplete
CWE-532
Insertion of Sensitive Information into Log File
Abstraction
Base
Structure
Simple
Likelihood of Exploit
Medium
Understand the problem
What is the problem?
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Implementation
Lifecycle phase
Operation
Risk
What does successful exploitation lead to?
Read Application Data
Defence
How is it prevented and fixed?
Architecture and Design · Implementation
Defence to apply across several lifecycle phases
Detail
Architecture and Design · Implementation
Defence to apply across several lifecycle phases
Distribution
Distribution aşaması savunması
Detail
Distribution
Distribution aşaması savunması
Operation
Operational defence
Detail
Operation
Operational defence
Implementation
Implementation-phase defence
Detail
Implementation
Implementation-phase defence
Verification
How is it detected?
Automated Static Analysis
HighMITRE diagram
Weakness relationships and flow
