Skip to main content

CWEs that violate the OWASP Mobile standard

The following table lists all the CWEs that might cause an application to not pass a policy that includes an OWASP Mobile policy rule.

CWE IDCWE nameSAST supportVeracode severityYears on list
15External Control of System or Configuration SettingYes4 - High2016
73External Control of File Name or PathYes3 - Medium2016
77Improper Neutralization of Special Elements in a CommandYes5 - Very High (Critical)2016
78Improper Neutralization of Special Elements in an OS CommandYes5 - Very High (Critical)2016
80Improper Neutralization of Script Related HTML TagsYes3 - Medium2016
88Improper Neutralization of Argument DelimetersYes3 - Medium2016
89Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)Yes4 - High2016
114Process ControlYes5 - Very High (Critical)2016
183Permissive List of Allowed InputsYes3 - Medium2016
201Information Exposure Through Sent DataYes2 - Low2016
209Information Exposure Through an Error MessageYes2 - Low2016
215Information Exposure Through Debug InformationYes2 - Low2016
242Use of Inherently Dangerous FunctionYes5 - Very High (Critical)2016
252Unchecked Return ValueYes2 - Low2016
256Unprotected Storage of CredentialsYes3 - Medium2016
259Use of Hard-coded PasswordYes3 - Medium2016
287Improper AuthenticationYes4 - High2016
296Improper Following of a Certificate's Chain of TrustNo3 - Medium2016
297Improper Validation of Certificate with Host MismatchYes3 - Medium2016
311Missing Encryption of Sensitive DataYes3 - Medium2016
312Cleartext Storage of Sensitive InformationYes3 - Medium2016
313Cleartext Storage in a File or on DiskYes3 - Medium2016
316Cleartext Storage of Sensitive Information in MemoryYes3 - Medium2016
319Cleartext Transmission of Sensitive InformationYes3 - Medium2016
321Use of Hard-coded Cryptographic KeyYes3 - Medium2016
326Inadequate Encryption StrengthYes3 - Medium2016
327Use of a Broken or Risky Cryptographic AlgorithmYes3 - Medium2016
329Not Using a Random IV with CBC ModeYes2 - Low2016
331Insufficient EntropyYes3 - Medium2016
345Insufficient Verification of Data AuthenticityYes4 - High2016
347Improper Verification of Cryptographic SignatureYes2 - Low2016
354Improper Validation of Integrity Check ValueYes3 - Medium2016
377Insecure Temporary FileYes3 - Medium2016
378Creation of Temporary File With Insecure PermissionsNo3 - Medium2016
404Improper Resource ShutdownYes0 - Informational2016
415Double FreeYes3 - Medium2016
416Use After FreeYes2 - Low2016
470Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)Yes3 - Medium2016
489Leftover Debug CodeYes3 - Medium2016
497Exposure of System Data to an Unauthorized Control SphereYes2 - Low2016
501Trust Boundary ViolationYes0 - Informational2016
506Embedded Malicious CodeYes4 - High2016
511Logic/Time BombYes5 - Very High (Critical)2016
514Covert ChannelYes2 - Low2016
522Insufficiently Protected CredentialsYes3 - Medium2016
601URL Redirection to Untrusted SiteYes3 - Medium2016
614Sensitive Cookie without Secure AttributeYes2 - Low2016
676Use of Potentially Dangerous FunctionYes3 - Medium2016
693Protection Mechanism FailureYes3 - Medium2016
732Incorrect Permission Assignment for Critical ResourceYes3 - Medium2016
757Selection of Less Secure Algorithm During NegotiationYes3 - Medium2016
798Use of Hard-coded CredentialsYes3 - Medium2016