COMMON WEAKNESS ENUMERATIONIncomplete
CWE-613
Insufficient Session Expiration
Abstraction
Base
Structure
Simple
Likelihood of Exploit
Medium
Understand the problem
What is the problem?
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Implementation
Risk
What does successful exploitation lead to?
Bypass Protection Mechanism
Defence
How is it prevented and fixed?
Implementation
Implementation-phase defence
Detail
Implementation
Implementation-phase defence
Verification