Skip to main content

CWEs that violate the OWASP Mobile standard

The following table lists all the CWEs that may cause an application to not pass a policy that includes an OWASP Mobile policy rule.

CWE IDCWE nameStatic supportVeracode severityYears on list
15External Control of System or Configuration SettingX4 - High2016
73External Control of File Name or PathX3 - Medium2016
77Improper Neutralization of Special Elements in a CommandX5 - Very High (Critical)2016
78Improper Neutralization of Special Elements in an OS CommandX5 - Very High (Critical)2016
80Improper Neutralization of Script Related HTML TagsX3 - Medium2016
88Improper Neutralization of Argument DelimetersX3 - Medium2016
89Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)X4 - High2016
114Process ControlX5 - Very High (Critical)2016
183Permissive List of Allowed InputsX3 - Medium2016
201Information Exposure Through Sent DataX2 - Low2016
209Information Exposure Through an Error MessageX2 - Low2016
215Information Exposure Through Debug InformationX2 - Low2016
242Use of Inherently Dangerous FunctionX5 - Very High (Critical)2016
252Unchecked Return ValueX2 - Low2016
256Unprotected Storage of CredentialsX3 - Medium2016
259Use of Hard-coded PasswordX3 - Medium2016
287Improper AuthenticationX4 - High2016
296Improper Following of a Certificate's Chain of Trust3 - Medium2016
297Improper Validation of Certificate with Host MismatchX3 - Medium2016
311Missing Encryption of Sensitive DataX3 - Medium2016
312Cleartext Storage of Sensitive InformationX3 - Medium2016
313Cleartext Storage in a File or on DiskX3 - Medium2016
316Cleartext Storage of Sensitive Information in MemoryX3 - Medium2016
319Cleartext Transmission of Sensitive InformationX3 - Medium2016
321Use of Hard-coded Cryptographic KeyX3 - Medium2016
326Inadequate Encryption StrengthX3 - Medium2016
327Use of a Broken or Risky Cryptographic AlgorithmX3 - Medium2016
329Not Using a Random IV with CBC ModeX2 - Low2016
331Insufficient EntropyX3 - Medium2016
345Insufficient Verification of Data AuthenticityX4 - High2016
347Improper Verification of Cryptographic SignatureX2 - Low2016
354Improper Validation of Integrity Check ValueX3 - Medium2016
377Insecure Temporary FileX3 - Medium2016
378Creation of Temporary File With Insecure Permissions3 - Medium2016
404Improper Resource ShutdownX0 - Informational2016
415Double FreeX3 - Medium2016
416Use After FreeX2 - Low2016
470Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)X3 - Medium2016
489Leftover Debug CodeX3 - Medium2016
497Exposure of System Data to an Unauthorized Control SphereX2 - Low2016
501Trust Boundary ViolationX0 - Informational2016
506Embedded Malicious CodeX4 - High2016
511Logic/Time BombX5 - Very High (Critical)2016
514Covert ChannelX2 - Low2016
522Insufficiently Protected CredentialsX3 - Medium2016
601URL Redirection to Untrusted SiteX3 - Medium2016
614Sensitive Cookie without Secure AttributeX2 - Low2016
676Use of Potentially Dangerous FunctionX3 - Medium2016
693Protection Mechanism FailureX3 - Medium2016
732Incorrect Permission Assignment for Critical ResourceX3 - Medium2016
757Selection of Less Secure Algorithm During NegotiationX3 - Medium2016
798Use of Hard-coded CredentialsX3 - Medium2016