CWEs that violate the OWASP Mobile standard
The following table lists all the CWEs that might cause an application to not pass a policy that includes an OWASP Mobile policy rule.
| CWE ID | CWE name | SAST support | Veracode severity | Years on list |
|---|---|---|---|---|
| 15 | External Control of System or Configuration Setting | Yes | 4 - High | 2016 |
| 73 | External Control of File Name or Path | Yes | 3 - Medium | 2016 |
| 77 | Improper Neutralization of Special Elements in a Command | Yes | 5 - Very High (Critical) | 2016 |
| 78 | Improper Neutralization of Special Elements in an OS Command | Yes | 5 - Very High (Critical) | 2016 |
| 80 | Improper Neutralization of Script Related HTML Tags | Yes | 3 - Medium | 2016 |
| 88 | Improper Neutralization of Argument Delimeters | Yes | 3 - Medium | 2016 |
| 89 | Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) | Yes | 4 - High | 2016 |
| 114 | Process Control | Yes | 5 - Very High (Critical) | 2016 |
| 183 | Permissive List of Allowed Inputs | Yes | 3 - Medium | 2016 |
| 201 | Information Exposure Through Sent Data | Yes | 2 - Low | 2016 |
| 209 | Information Exposure Through an Error Message | Yes | 2 - Low | 2016 |
| 215 | Information Exposure Through Debug Information | Yes | 2 - Low | 2016 |
| 242 | Use of Inherently Dangerous Function | Yes | 5 - Very High (Critical) | 2016 |
| 252 | Unchecked Return Value | Yes | 2 - Low | 2016 |
| 256 | Unprotected Storage of Credentials | Yes | 3 - Medium | 2016 |
| 259 | Use of Hard-coded Password | Yes | 3 - Medium | 2016 |
| 287 | Improper Authentication | Yes | 4 - High | 2016 |
| 296 | Improper Following of a Certificate's Chain of Trust | No | 3 - Medium | 2016 |
| 297 | Improper Validation of Certificate with Host Mismatch | Yes | 3 - Medium | 2016 |
| 311 | Missing Encryption of Sensitive Data | Yes | 3 - Medium | 2016 |
| 312 | Cleartext Storage of Sensitive Information | Yes | 3 - Medium | 2016 |
| 313 | Cleartext Storage in a File or on Disk | Yes | 3 - Medium | 2016 |
| 316 | Cleartext Storage of Sensitive Information in Memory | Yes | 3 - Medium | 2016 |
| 319 | Cleartext Transmission of Sensitive Information | Yes | 3 - Medium | 2016 |
| 321 | Use of Hard-coded Cryptographic Key | Yes | 3 - Medium | 2016 |
| 326 | Inadequate Encryption Strength | Yes | 3 - Medium | 2016 |
| 327 | Use of a Broken or Risky Cryptographic Algorithm | Yes | 3 - Medium | 2016 |
| 329 | Not Using a Random IV with CBC Mode | Yes | 2 - Low | 2016 |
| 331 | Insufficient Entropy | Yes | 3 - Medium | 2016 |
| 345 | Insufficient Verification of Data Authenticity | Yes | 4 - High | 2016 |
| 347 | Improper Verification of Cryptographic Signature | Yes | 2 - Low | 2016 |
| 354 | Improper Validation of Integrity Check Value | Yes | 3 - Medium | 2016 |
| 377 | Insecure Temporary File | Yes | 3 - Medium | 2016 |
| 378 | Creation of Temporary File With Insecure Permissions | No | 3 - Medium | 2016 |
| 404 | Improper Resource Shutdown | Yes | 0 - Informational | 2016 |
| 415 | Double Free | Yes | 3 - Medium | 2016 |
| 416 | Use After Free | Yes | 2 - Low | 2016 |
| 470 | Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) | Yes | 3 - Medium | 2016 |
| 489 | Leftover Debug Code | Yes | 3 - Medium | 2016 |
| 497 | Exposure of System Data to an Unauthorized Control Sphere | Yes | 2 - Low | 2016 |
| 501 | Trust Boundary Violation | Yes | 0 - Informational | 2016 |
| 506 | Embedded Malicious Code | Yes | 4 - High | 2016 |
| 511 | Logic/Time Bomb | Yes | 5 - Very High (Critical) | 2016 |
| 514 | Covert Channel | Yes | 2 - Low | 2016 |
| 522 | Insufficiently Protected Credentials | Yes | 3 - Medium | 2016 |
| 601 | URL Redirection to Untrusted Site | Yes | 3 - Medium | 2016 |
| 614 | Sensitive Cookie without Secure Attribute | Yes | 2 - Low | 2016 |
| 676 | Use of Potentially Dangerous Function | Yes | 3 - Medium | 2016 |
| 693 | Protection Mechanism Failure | Yes | 3 - Medium | 2016 |
| 732 | Incorrect Permission Assignment for Critical Resource | Yes | 3 - Medium | 2016 |
| 757 | Selection of Less Secure Algorithm During Negotiation | Yes | 3 - Medium | 2016 |
| 798 | Use of Hard-coded Credentials | Yes | 3 - Medium | 2016 |